Buffer Overflow Vulnerability in Tenda WH450 Remote Access Component
CVE-2025-15047
Key Information:
Badges
What is CVE-2025-15047?
A vulnerability in the Tenda WH450 device allows attackers to exploit a stack-based buffer overflow through the remote manipulation of the 'Username' argument in the /goform/PPTPDClient component. This flaw in the HTTP Request Handler can potentially permit unauthorized access and manipulation of data, leading to significant security risks. Given that the exploit vector has been made public, users are encouraged to apply necessary precautions and updates to safeguard their devices.
Affected Version(s)
WH450 1.0.0.18
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved