Stack Overflow Vulnerability in Tenda W18E Router
CVE-2025-29218

6.5MEDIUM

Key Information:

Vendor
Tenda
Vendor
CVE Published:
20 March 2025

Summary

A stack overflow vulnerability exists in the Tenda W18E router at the wifiPwd parameter in the /goform/setModules endpoint. This flaw could be exploited by attackers through specially crafted POST requests, potentially leading to a Denial of Service (DoS) situation. The vulnerability highlights the importance of secure coding practices in network device firmware to prevent malicious exploitation and protect users from service disruptions.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.