Buffer Overflow Vulnerability in Tenda WH450 Router
CVE-2025-15177
Key Information:
Badges
What is CVE-2025-15177?
A buffer overflow vulnerability exists in the Tenda WH450 Router affecting version 1.0.0.18. The issue is found within the /goform/SetIpBind component of the HTTP Request Handler. An attacker can exploit this vulnerability by manipulating the 'page' parameter, leading to a stack-based buffer overflow. This could allow for remote code execution, potentially compromising the device's integrity. The exploit has been publicly disclosed, making it essential for users to apply necessary security measures.
Affected Version(s)
WH450 1.0.0.18
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved