CVE-2025-12212
8.8Tenda · O3V2.0
A stack-based buffer overflow exists in the Tenda O3V2.0 firmware via the upnpEn parameter in the /goform/setNetworkService endpoint, allowing remote code execution.
Executive summary
A critical stack-based buffer overflow in Tenda O3V2.0 firmware allows remote attackers to execute arbitrary code on the affected device.
Vulnerability
The vulnerability exists within the setNetworkService and getNetworkService functions of the /goform/setNetworkService endpoint. An attacker with low-level privileges can supply an overly long value to the upnpEn parameter, which triggers a stack-based buffer overflow during memory operations.
Business impact
Successful exploitation of this vulnerability permits a remote attacker to gain control over the affected network equipment, potentially leading to unauthorized network access, traffic interception, or complete system compromise. Given the CVSS score of 8.8, this flaw represents a significant risk to organizational infrastructure, as it facilitates lateral movement into internal segments from the edge.
Remediation
Immediate Action: Contact Tenda support or check the official Tenda website for firmware updates addressing this buffer overflow. If no patch is available, isolate the affected device from the internet or restrict access to the management interface.
Proactive Monitoring: Monitor network traffic for unusual POST requests directed at /goform/setNetworkService or /goform/getNetworkService. Review system logs for signs of service crashes or unauthorized configuration changes.
Compensating Controls: Implement an edge firewall or Web Application Firewall (WAF) to filter and block malicious traffic containing abnormally long upnpEn parameter values. Disable Universal Plug and Play (UPnP) features on the device if they are not strictly required for business operations.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the technical write-up provided by the researcher at GitHub.
Analyst recommendation
The presence of a functional proof-of-concept makes this vulnerability an immediate target for automated scanning and exploitation. Administrators should prioritize the identification of Tenda O3V2.0 units within their environment and apply vendor-supplied firmware updates as soon as they become available. Until a patch is confirmed, restricting management access to known-trusted IP addresses is strongly recommended.
More Tenda CVEs
Sources
Originally found and disclosed by wxhwxhwxh_ (VulDB User), per the CVE Program record.
- VDB-329882 | Tenda O3 setNetworkService GetValue stack-based overflow Vulnerability database entry
- VDB-329882 | CTI Indicators (IOB, IOC, IOA)
- Submit #673267 | Tenda O3 V1.0.0.10(2478) Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn