CVE-2025-11586

8.8

Tenda · AC7

A stack-based buffer overflow in the Tenda AC7 firmware allows remote attackers to trigger a device crash or remote code execution via the newVersion parameter in the /goform/setNotUpgrade endpoint.

Executive summary

A critical stack-based buffer overflow vulnerability in Tenda AC7 routers allows authenticated attackers to trigger remote code execution or system instability.

Vulnerability

The vulnerability exists in the /goform/setNotUpgrade interface, where the newVersion parameter fails to perform adequate input size validation. This allows a low-privileged authenticated attacker to overflow a stack buffer when the value is later retrieved by the /goform/GetRouterStatus routine.

Business impact

Successful exploitation of this flaw can lead to a complete compromise of the router, including unauthorized remote code execution. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to network-wide interception, data exfiltration, or the permanent denial of service of critical infrastructure.

Remediation

Immediate Action: Users should visit the official Tenda support website to check for and apply the latest firmware updates that resolve this memory corruption flaw.

Proactive Monitoring: Security teams should monitor network traffic for suspicious POST requests directed at /goform/setNotUpgrade and unusual router status queries.

Compensating Controls: Deploy a Web Application Firewall or network-level access control list to restrict access to the web management interface of the router to authorized management workstations only.

Exploitation status

Public Exploit Available: Yes, a functional proof-of-concept exploit is available via the researcher's technical write-up on GitHub.

Analyst recommendation

The severity of this vulnerability, combined with the availability of a public proof-of-concept, necessitates immediate action. Administrators must prioritize patching the affected Tenda AC7 devices to the latest available firmware version to mitigate the risk of remote code execution and unauthorized system access.

More Tenda CVEs

Sources

Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.