Stack-Based Buffer Overflow in Tenda Router
CVE-2025-7549
Key Information:
Badges
What is CVE-2025-7549?
A vulnerability in the Tenda FH1201 router has been identified, specifically within the frmL7ProtForm function located in the /goform/L7Prot file. This security issue is triggered through improper handling of the 'page' argument, which can lead to a stack-based buffer overflow. Such a flaw allows attackers to exploit the router remotely, potentially compromising the device and its network. Given that this exploit has been disclosed publicly, it is crucial for users of affected versions to apply necessary updates and mitigations to protect themselves.
Affected Version(s)
FH1201 1.2.0.14(408)
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved