CVE-2025-11389

8.8

Tenda · AC15

A stack-based buffer overflow exists in Tenda AC15 firmware version 15.03.05.18, allowing remote attackers to trigger memory corruption via the enable parameter in the /goform/saveAutoQos endpoint.

Executive summary

A critical stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to compromise device integrity or cause system crashes.

Vulnerability

The device fails to perform input length validation when processing the enable parameter within the /goform/saveAutoQos endpoint. A remote, authenticated attacker can leverage this memory corruption flaw to overwrite the stack, potentially leading to arbitrary code execution or a denial of service.

Business impact

Successful exploitation of this vulnerability poses a severe risk to network infrastructure. Because the Tenda AC15 functions as a gateway device, an attacker gaining control could intercept traffic, modify network configurations, or utilize the device as a pivot point for further lateral movement within the internal network. Given the CVSS score of 8.8, this vulnerability is classified as High severity and requires immediate attention to prevent unauthorized access to critical network segments.

Remediation

Immediate Action: Since no vendor patch is currently confirmed, administrators should restrict access to the device management interface to trusted IP addresses only and disable remote management features.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /goform/saveAutoQos and watch for unexpected device reboots or instability which may indicate exploitation attempts.

Compensating Controls: Implement a perimeter firewall policy that blocks external access to the device web interface, ensuring that the management console is only reachable from a dedicated, secure management VLAN.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists via the technical write-up on GitHub.

Analyst recommendation

The presence of a public proof-of-concept combined with the potential for remote code execution makes this a significant risk for any organization utilizing the affected Tenda AC15 hardware. Security teams should treat this device as compromised if it has been exposed to the internet and prioritize the implementation of network-level access controls to isolate the management interface until the vendor releases a secure firmware update.

More Tenda CVEs

Sources

Originally found and disclosed by yhryhryhr_mie (VulDB User), per the CVE Program record.