CVE-2025-12214
8.8Tenda · O3V2.0
A stack-based buffer overflow vulnerability in Tenda O3V2.0 firmware allows remote attackers to trigger memory corruption via the enable parameter in the /goform/sysAutoReboot endpoint.
Executive summary
A critical stack-based buffer overflow vulnerability in Tenda O3V2.0 firmware allows for remote code execution and system instability, necessitating immediate attention.
Vulnerability
This vulnerability involves a stack-based buffer overflow triggered by improper input validation within the SetValue and GetValue functions. An authenticated attacker can send a malicious payload to the /goform/sysAutoReboot endpoint, which is subsequently processed in a way that exceeds stack memory boundaries.
Business impact
The vulnerability poses a severe risk to network integrity and device availability. Successful exploitation could lead to arbitrary code execution, allowing an attacker to gain control over the affected wireless bridge, potentially facilitating lateral movement within the network or causing persistent denial-of-service conditions. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could result in significant operational disruption.
Remediation
Immediate Action: Since a vendor patch is currently unknown, administrators should restrict network access to the management interface of the affected devices to trusted IP addresses only.
Proactive Monitoring: Monitor device logs for unusual POST requests directed at the /goform/sysAutoReboot or /goform/getNetworkService endpoints.
Compensating Controls: Implement strict firewall rules to prevent unauthorized access to the web management interface of the Tenda O3 devices from untrusted network segments.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up provided by the researcher on GitHub.
Analyst recommendation
Given the availability of a functional proof-of-concept and the high CVSS severity, this vulnerability presents a credible threat to infrastructure using Tenda O3 devices. Security teams should prioritize isolating these devices from public-facing networks and implement strict access control lists until an official firmware update is released by the manufacturer.
More Tenda CVEs
Sources
Originally found and disclosed by yhryhryhr_tutu (VulDB User), per the CVE Program record.
- VDB-329884 | Tenda O3 sysAutoReboot GetValue stack-based overflow Vulnerability database entry
- VDB-329884 | CTI Indicators (IOB, IOC, IOA)
- Submit #673269 | Tenda O3 V1.0.0.10(2478) Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn