CVE-2025-63834

A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac18_firmware:15.03.05.05:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac18:-:*:*:*:*:*:*:*

History

01 Dec 2025, 20:15

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de Cross-Site Scripting (XSS) almacenado fue descubierta en Tenda AC18 v15.03.05.05_multi. La vulnerabilidad existe en el parámetro ssid de la configuración inalámbrica. Atacantes remotos pueden inyectar cargas útiles maliciosas que se ejecutan cuando cualquier usuario visita la página de inicio del router.

17 Nov 2025, 18:30

Type Values Removed Values Added
CPE cpe:2.3:o:tenda:ac18_firmware:15.03.05.05:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac18:-:*:*:*:*:*:*:*
References () https://github.com/babraink/cve_report/blob/main/cve_report/tenda/tendaAC18/wifiset_ssid_xss/README.md - () https://github.com/babraink/cve_report/blob/main/cve_report/tenda/tendaAC18/wifiset_ssid_xss/README.md - Exploit, Third Party Advisory
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
First Time Tenda ac18
Tenda ac18 Firmware
Tenda

10 Nov 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-10 17:15

Updated : 2025-12-01 20:15


NVD link : CVE-2025-63834

Mitre link : CVE-2025-63834

CVE.ORG link : CVE-2025-63834


JSON object : View

Products Affected

tenda

  • ac18
  • ac18_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')