CVE-2025-11325

8.8

Tenda · AC18

Tenda AC18 firmware 15.03.05.19(6318) is vulnerable to a stack-based buffer overflow in the /goform/fast_setting_pppoe_set endpoint via the username parameter, allowing remote code execution.

Executive summary

A critical stack-based buffer overflow vulnerability exists in Tenda AC18 routers that allows remote attackers to compromise device integrity.

Vulnerability

This is a stack-based buffer overflow (CWE-121) occurring within the /goform/fast_setting_pppoe_set endpoint. An attacker with low-level privileges can supply an oversized string to the username parameter, triggering memory corruption that may lead to remote code execution.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain unauthorized control over the affected Tenda router. Given the CVSS score of 8.8, this poses a significant risk to network availability and data confidentiality, as attackers could potentially intercept traffic, pivot into internal network segments, or render the device inoperable, leading to severe operational disruption.

Remediation

Immediate Action: As no official patch is currently available, users should restrict access to the device management interface to trusted internal networks only and disable remote administration features.

Proactive Monitoring: Monitor network traffic for anomalous POST requests directed at /goform/fast_setting_pppoe_set and investigate any unexpected device reboots or service instability.

Compensating Controls: Implement a Web Application Firewall (WAF) or network-level access control list (ACL) to block unauthorized access to the router administrative interface from untrusted sources.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the research write-up by the vulnerability reporter.

Analyst recommendation

The vulnerability is severe due to the potential for remote code execution and the existence of public exploit code. Administrators must prioritize isolating vulnerable Tenda AC18 devices from public-facing exposure immediately. Monitor vendor communication channels for firmware updates and apply them as soon as they become available to permanently resolve the underlying memory corruption flaw.

More Tenda CVEs

Sources

Originally found and disclosed by yhryhryhr_miemie (VulDB User), per the CVE Program record.