CVE-2025-12214

8.8

Tenda · O3V2.0

A stack-based buffer overflow vulnerability in Tenda O3V2.0 firmware allows remote attackers to trigger memory corruption via the enable parameter in the /goform/sysAutoReboot endpoint.

Executive summary

A critical stack-based buffer overflow vulnerability in Tenda O3V2.0 firmware allows for remote code execution and system instability, necessitating immediate attention.

Vulnerability

This vulnerability involves a stack-based buffer overflow triggered by improper input validation within the SetValue and GetValue functions. An authenticated attacker can send a malicious payload to the /goform/sysAutoReboot endpoint, which is subsequently processed in a way that exceeds stack memory boundaries.

Business impact

The vulnerability poses a severe risk to network integrity and device availability. Successful exploitation could lead to arbitrary code execution, allowing an attacker to gain control over the affected wireless bridge, potentially facilitating lateral movement within the network or causing persistent denial-of-service conditions. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could result in significant operational disruption.

Remediation

Immediate Action: Since a vendor patch is currently unknown, administrators should restrict network access to the management interface of the affected devices to trusted IP addresses only.

Proactive Monitoring: Monitor device logs for unusual POST requests directed at the /goform/sysAutoReboot or /goform/getNetworkService endpoints.

Compensating Controls: Implement strict firewall rules to prevent unauthorized access to the web management interface of the Tenda O3 devices from untrusted network segments.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up provided by the researcher on GitHub.

Analyst recommendation

Given the availability of a functional proof-of-concept and the high CVSS severity, this vulnerability presents a credible threat to infrastructure using Tenda O3 devices. Security teams should prioritize isolating these devices from public-facing networks and implement strict access control lists until an official firmware update is released by the manufacturer.

More Tenda CVEs

Sources

Originally found and disclosed by yhryhryhr_tutu (VulDB User), per the CVE Program record.