Stack-based Buffer Overflow in Tenda W12 and i24 Products
CVE-2025-3802
Key Information:
Badges
Summary
A vulnerability has been identified in Tenda W12 and i24 products, specifically affecting the cgiPingSet function in the /bin/httpd file. The issue arises from improper handling of the pingIP argument, which can result in a stack-based buffer overflow. This vulnerability can be exploited remotely, allowing potential attackers to manipulate the system from afar. The exploit has been publicly disclosed, emphasizing the importance of immediate vulnerability management and patching measures for affected users.
Affected Version(s)
i24 3.0.0.4(2887)
i24 3.0.0.5(3644)
W12 3.0.0.4(2887)
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved