Stack-based Buffer Overflow in Tenda W12 Router
CVE-2025-11549
Key Information:
Badges
What is CVE-2025-11549?
A stack-based buffer overflow vulnerability exists in the Tenda W12 router, specifically in the wifiMacFilterSet
function within the HTTP Request Handler component. By manipulating the MAC address argument, an attacker can exploit this vulnerability remotely, potentially leading to unauthorized access and control over the affected device. The nature of the vulnerability allows it to be exploited from a distance, increasing the risk to users operating affected versions of the router. This vulnerability has been publicly disclosed, underscoring the importance of immediate remediation for users.
Affected Version(s)
W12 3.0.0.6(3948)
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved