Buffer Overflow Vulnerability in Tenda AC20 Router
CVE-2025-8940
Key Information:
Badges
What is CVE-2025-8940?
A serious buffer overflow vulnerability exists in the Tenda AC20 router within the strcpy function located in /goform/saveParentControlInfo. By manipulating the argument 'Time', unauthorized remote attackers can exploit this flaw to execute arbitrary code. As the exploit has been made public, it poses significant risks to users still operating vulnerable versions of the device, encouraging immediate review and remediation.
Affected Version(s)
AC20 16.03.08.0
AC20 16.03.08.1
AC20 16.03.08.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved