CVE-2025-15010

9.8

Tenda · WH450

A stack-based buffer overflow in the Tenda WH450 router allows remote attackers to execute arbitrary code or cause a denial of service via the page parameter in the /goform/SafeUrlFilter endpoint.

Executive summary

A critical stack-based buffer overflow vulnerability in Tenda WH450 firmware version 1.0.0.18 poses a severe risk of remote code execution.

Vulnerability

This is a stack-based buffer overflow (CWE-121) occurring within the /goform/SafeUrlFilter HTTP request handler. An unauthenticated attacker can trigger this vulnerability by sending a crafted HTTP request with an excessively long page parameter, leading to memory corruption and potential arbitrary code execution.

Business impact

Successful exploitation of this vulnerability allows a remote attacker to gain full control over the affected router, which can lead to unauthorized network access, interception of sensitive traffic, and complete system compromise. Given the CVSS score of 9.8, this flaw represents a critical threat to organizational infrastructure, potentially facilitating lateral movement into protected internal networks.

Remediation

Immediate Action: Discontinue use of the affected Tenda WH450 device or isolate it from public-facing network segments until a vendor-supplied firmware update is applied. Verify the Tenda support portal for the latest available firmware release.

Proactive Monitoring: Monitor network traffic for suspicious HTTP requests targeting the /goform/SafeUrlFilter endpoint or unusual router behavior, such as unexpected reboots or crashes.

Compensating Controls: Implement strict ingress filtering on the network perimeter to block unauthorized access to the router management interface. If possible, place the device behind a robust firewall and disable remote management features.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the security researcher's technical write-up linked in the vulnerability records.

Analyst recommendation

The critical nature of this buffer overflow, combined with the availability of public proof-of-concept code, necessitates immediate attention. Organizations utilizing Tenda WH450 routers must prioritize patching or isolating these devices to prevent exploitation. Failure to mitigate this vulnerability exposes the network to high-impact remote compromise.

More Tenda CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Analyst report written

Sources

Originally found and disclosed by z472421519 (VulDB User), per the CVE Program record.