Buffer Overflow Vulnerability in Tenda AC7 Router
CVE-2025-3346
8.7HIGH
What is CVE-2025-3346?
A vulnerability exists in the Tenda AC7 router, specifically within the formSetPPTPServer function of the /goform/SetPptpServerCfg file. This flaw allows an attacker to manipulate the pptp_server_start_ip and pptp_server_end_ip parameters, resulting in a buffer overflow. The exploit can be executed remotely, potentially compromising the security of the device. Public disclosures indicate that this vulnerability is known and may be targeted by attackers.
Affected Version(s)
AC7 15.03.06.44