CVE-2025-11387
8.8Tenda · AC15
A stack-based buffer overflow in Tenda AC15 firmware version 15.03.05.18 allows remote attackers to trigger memory corruption via the password parameter in the /goform/fast_setting_pppoe_set endpoint.
Executive summary
A critical stack-based buffer overflow vulnerability in Tenda AC15 routers may allow remote attackers to achieve code execution or cause system crashes.
Vulnerability
The flaw resides in the handling of the password parameter within the /goform/fast_setting_pppoe_set endpoint, where insufficient bounds checking during configuration storage leads to a stack-based buffer overflow. While the CVSS vector indicates low privilege requirements, the vulnerability is reachable remotely and permits memory corruption.
Business impact
Successful exploitation of this vulnerability can result in full system compromise, including unauthorized remote code execution or denial of service on affected networking hardware. Given the CVSS score of 8.8, this represents a high severity risk that could lead to lateral movement within a network or interception of traffic, significantly impacting the integrity and availability of organizational communications.
Remediation
Immediate Action: Since no official patch is currently identified, administrators should immediately restrict access to the management interface of the Tenda AC15 to trusted internal networks only.
Proactive Monitoring: Monitor device logs for unusual POST requests to the /goform/fast_setting_pppoe_set endpoint and unexpected device reboots, which may indicate crash attempts.
Compensating Controls: Implement network-level access control lists or a firewall to block external access to the router's web management interface, effectively mitigating the remote attack vector.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists (attributed to the technical write-up provided in the referenced GitHub repository).
Analyst recommendation
Due to the severity of the memory corruption flaw and the availability of technical details for exploitation, immediate defensive action is required. Organizations utilizing Tenda AC15 hardware should prioritize disabling remote management interfaces and monitor for vendor-provided firmware updates to address this vulnerability permanently.
More Tenda CVEs
Sources
Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.
- VDB-327314 | Tenda AC15 fast_setting_pppoe_set stack-based overflow Vulnerability database entry
- VDB-327314 | CTI Indicators (IOB, IOC, IOA)
- Submit #664970 | Tenda AC15 V15.03.05.18 Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn