CVE-2025-11328
8.8Tenda · AC18
A stack-based buffer overflow in the Tenda AC18 router allows remote attackers to trigger memory corruption via the ddnsEn parameter in the /goform/SetDDNSCfg endpoint.
Executive summary
A critical stack-based buffer overflow vulnerability in the Tenda AC18 router could allow an attacker to achieve remote code execution or cause a denial of service.
Vulnerability
This is a stack-based buffer overflow (CWE-121) occurring within the /goform/SetDDNSCfg endpoint. The vulnerability is triggered when the ddnsEn parameter is manipulated, as the application fails to perform adequate length restrictions on the input, allowing an authenticated user to overwrite memory.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high level of severity. Successful exploitation could lead to full system compromise, allowing an attacker to execute arbitrary code with elevated privileges, potentially resulting in complete loss of confidentiality, integrity, and availability for the affected network device.
Remediation
Immediate Action: As no official patch is currently available, administrators should immediately isolate the affected Tenda AC18 devices from external networks and restrict access to the management interface.
Proactive Monitoring: Monitor network traffic for anomalous POST requests directed at the /goform/SetDDNSCfg endpoint and check system logs for signs of unexpected reboots or crashes.
Compensating Controls: Implement strict firewall rules to ensure that the router management interface is not exposed to the public internet, and restrict administrative access to a trusted, internal management VLAN.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up provided by the vulnerability researcher.
Analyst recommendation
Given the high CVSS score and the public availability of exploit code, this vulnerability poses a significant risk to network infrastructure. Administrators must prioritize restricting access to the management interface of the affected Tenda AC18 routers immediately until an official firmware update from the vendor is released and applied.
More Tenda CVEs
Sources
Originally found and disclosed by yhryhryhr_ (VulDB User), per the CVE Program record.
- VDB-327211 | Tenda AC18 SetDDNSCfg stack-based overflow Vulnerability database entry
- VDB-327211 | CTI Indicators (IOB, IOC, IOA)
- Submit #664533 | Tenda AC18 V15.03.05.19(6318) Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn