CVE-2025-1853

A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical. This issue affects the function sub_49E098 of the file /goform/SetIpMacBind of the component Parameter Handler. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/Raining-101/IOT_cve/blob/main/tenda-ac8_sub_49E098.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.298121 Permissions Required VDB Entry
https://vuldb.com/?id.298121 Third Party Advisory VDB Entry
https://vuldb.com/?submit.505374 Third Party Advisory VDB Entry
https://www.tenda.com.cn/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac8_firmware:16.03.34.06:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac8:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-03 06:15

Updated : 2025-03-05 21:28


NVD link : CVE-2025-1853

Mitre link : CVE-2025-1853

CVE.ORG link : CVE-2025-1853


JSON object : View

Products Affected

tenda

  • ac8
  • ac8_firmware
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write