CVE-2025-11326
8.8Tenda · AC18
A stack-based buffer overflow in the Tenda AC18 router allows remote attackers to execute arbitrary code via the wifi_chkHz parameter in the /goform/WifiMacFilterSet endpoint.
Executive summary
A critical stack-based buffer overflow vulnerability in Tenda AC18 routers could allow remote attackers to achieve unauthorized code execution.
Vulnerability
The device is susceptible to a stack-based buffer overflow due to improper length validation within the /goform/WifiMacFilterSet endpoint. An attacker with low-level privileges can trigger this memory corruption by sending a crafted POST request containing an oversized wifi_chkHz parameter.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the affected router. This level of compromise poses a severe risk to organizational network integrity, as it grants the attacker a foothold to intercept traffic, pivot into internal network segments, or disrupt critical connectivity. With a CVSS score of 8.8, this vulnerability is classified as High severity and requires immediate attention to prevent potential exploitation.
Remediation
Immediate Action: Users should immediately check the Tenda support website for firmware updates addressing this vulnerability and apply them to the affected AC18 devices.
Proactive Monitoring: Security teams should monitor network traffic for anomalous POST requests directed at the /goform/WifiMacFilterSet or /goform/WifiExtraSet endpoints.
Compensating Controls: Deploy a Web Application Firewall or router-level access control list to restrict access to the web management interface to trusted internal IP addresses only.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the technical write-up provided by the vulnerability researcher.
Analyst recommendation
Given the availability of a public proof-of-concept and the potential for remote code execution, this vulnerability represents a significant security risk to Tenda AC18 users. Administrators must prioritize the application of vendor patches as soon as they become available. If a patch cannot be applied immediately, restrict administrative access to the device management interface to minimize the attack surface.
More Tenda CVEs
Sources
Originally found and disclosed by yhryhryhr_tu (VulDB User), per the CVE Program record.
- VDB-327209 | Tenda AC18 WifiMacFilterSet stack-based overflow Vulnerability database entry
- VDB-327209 | CTI Indicators (IOB, IOC, IOA)
- Submit #664530 | Tenda AC18 V15.03.05.19(6318) Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn