CVE-2025-15356

8.8

Tenda · AC20

A buffer overflow vulnerability in the Tenda AC20 router allows remote attackers to trigger memory corruption via the /goform/PowerSaveSet endpoint.

Executive summary

A critical remote buffer overflow vulnerability in Tenda AC20 routers poses a severe risk of unauthorized system control and potential execution of arbitrary code.

Vulnerability

This flaw involves a buffer overflow in the sscanf function within the /goform/PowerSaveSet file. The vulnerability is triggered by manipulating specific arguments such as powerSavingEn, time, powerSaveDelay, or ledCloseType, requiring low-privileged user access to initiate a remote attack.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high severity level. Successful exploitation may allow an attacker to gain unauthorized control over the router, potentially leading to full system compromise, network traffic interception, or service disruption, which significantly threatens organizational data confidentiality and operational integrity.

Remediation

Immediate Action: Since a specific patch is not currently confirmed, administrators should restrict access to the web management interface of the Tenda AC20 to trusted internal networks only.

Proactive Monitoring: Monitor firewall and network logs for unusual traffic patterns directed at the /goform/PowerSaveSet path or unexpected administrative login attempts.

Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) rule to inspect and block malicious payloads targeting the specified PowerSaveSet parameters.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical write-up provided by the researcher at GitHub.

Analyst recommendation

Given the availability of a public proof-of-concept and the high severity of this buffer overflow, immediate defensive measures are required. Administrators must prioritize isolating the affected hardware from public-facing exposure until a vendor-supplied firmware update is verified and applied to remediate the underlying memory corruption flaw.

More Tenda CVEs

Sources

Originally found and disclosed by xuanyu (VulDB User), per the CVE Program record.