CVE-2025-15008
7.3Tenda · WH450
A stack-based buffer overflow in the Tenda WH450 HTTP request handler allows remote attackers to trigger memory corruption via the page parameter.
Executive summary
A critical stack-based buffer overflow vulnerability in Tenda WH450 routers allows remote, unauthenticated attackers to execute arbitrary code or cause a denial of service.
Vulnerability
The vulnerability exists within the HTTP request handler for the /goform/L7Port endpoint, where a stack-based buffer overflow is triggered by supplying an excessively long value to the page parameter. This flaw allows remote, unauthenticated attackers to perform memory corruption, potentially leading to arbitrary code execution or service disruption.
Business impact
Successful exploitation of this vulnerability poses a severe risk to network infrastructure. Because the device is an edge router, compromise could lead to full loss of confidentiality, integrity, and availability for all traffic passing through the affected hardware. With a CVSS score of 7.3, this represents a high-severity threat that could facilitate unauthorized network access and persistent control over gateway devices.
Remediation
Immediate Action: There is currently no vendor-supplied patch available for this device. Administrators should immediately restrict access to the management interface to trusted internal networks only and disable remote management features.
Proactive Monitoring: Monitor network traffic for anomalous HTTP GET requests targeting /goform/L7Port, specifically looking for requests containing oversized parameters.
Compensating Controls: Implement a Web Application Firewall or network-level access control list to filter and block requests directed at the /goform/L7Port endpoint from untrusted sources.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the technical research documentation provided by the vulnerability reporter.
Analyst recommendation
Given the availability of a functional proof-of-concept and the lack of a vendor-provided security update, this vulnerability presents an immediate and elevated risk to Tenda WH450 deployments. Users must prioritize isolating these devices from the public internet and applying the recommended network-level compensating controls until a firmware update is released by the manufacturer.
More Tenda CVEs
Sources
Originally found and disclosed by z472421519 (VulDB User), per the CVE Program record.
- VDB-337714 | Tenda WH450 HTTP Request L7Port stack-based overflow Vulnerability database entry
- VDB-337714 | CTI Indicators (IOB, IOC, IOA)
- Submit #719317 | Tenda WH450 V1.0.0.18 Stack-based Buffer Overflow Third-party advisory
- Exploit / PoC
- Exploit / PoC
- tenda.com.cn