216.73.217.22

CVE-2025-63835

· Published 10/11/2025 17:15 · Modified 18/11/2025 17:16

Labels: CVE-2025-63835 2025-11-10CVE-2025-63835CWE-121CWE-787[email protected]

Essential information

Published
10/11/2025 17:15
Modified
18/11/2025 17:16
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attackers can exploit this vulnerability by sending oversized data to the guestSsid parameter, leading to denial of service (device crash) or potential remote code execution.

NVD status

Status
Modified — CVE has been amended by a source (CVE Primary CNA or another CNA). Analysis data supplied by the NVD may be no longer be accurate due to these changes.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tenda / ac18 firmware cpe:2.3:o:tenda:ac18_firmware:15.03.05.05:*:*:*:*:*:*:*
tenda / ac18 cpe:2.3:h:tenda:ac18:-:*:*:*:*:*:*:*

References