CVE-2025-11385
8.8Tenda · AC20
A buffer overflow vulnerability exists in the Tenda AC20 router within the sscanf function of the /goform/fast_setting_wifi_set endpoint, potentially allowing remote code execution.
Executive summary
A critical memory corruption vulnerability in Tenda AC20 routers allows remote attackers to trigger a buffer overflow, posing a severe risk of unauthorized code execution.
Vulnerability
The vulnerability resides in the sscanf function within the /goform/fast_setting_wifi_set file. By manipulating the timeZone argument, a remote attacker can trigger a buffer overflow, leading to memory corruption.
Business impact
Successful exploitation of this vulnerability can lead to a complete compromise of the affected router, resulting in unauthorized access to internal network traffic, potential data exfiltration, and significant service disruption. With a CVSS score of 8.8, this flaw represents a high-severity risk that could facilitate lateral movement into the broader corporate or home network infrastructure.
Remediation
Immediate Action: Update the Tenda AC20 firmware to the latest available version provided by the vendor to remediate the buffer overflow flaw.
Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/fast_setting_wifi_set endpoint and review system logs for signs of repeated service crashes or unexpected reboots.
Compensating Controls: Implement a Web Application Firewall (WAF) or equivalent network filter to block malicious payloads targeting the specified administrative endpoint if an immediate firmware update is not feasible.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up referenced by the CVE record.
Analyst recommendation
Given the availability of a public proof-of-concept and the high-severity nature of buffer overflow vulnerabilities in network hardware, organizations must prioritize patching this device. Administrators should verify the current firmware version against the affected list and apply the latest security updates immediately to mitigate the risk of remote code execution.
More Tenda CVEs
Sources
Originally found and disclosed by cymiao (VulDB User), per the CVE Program record.