Stack Overflow Vulnerability in Tenda AC9 Router Firmware
CVE-2025-45428
9.8CRITICAL
Summary
The Tenda AC9 Router firmware version V15.03.05.14_multi has a critical stack overflow vulnerability within the rebootTime parameter of the /goform/SetSysAutoRebbotCfg interface. This flaw allows an attacker to manipulate the stack memory, potentially leading to remote arbitrary code execution. Malicious users could exploit this vulnerability to gain unauthorized access and execute arbitrary commands on the affected device, compromising the security and functionality of the network.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved