CVE-2025-55564

7.5

Tenda · AC15

A stack overflow vulnerability exists in Tenda AC15 firmware version 15.03.05.19_multi_TD01, allowing an unauthenticated attacker to cause a denial of service via the list parameter.

Executive summary

A stack-based buffer overflow in Tenda AC15 firmware exposes devices to potential remote denial of service attacks by unauthenticated actors.

Vulnerability

This vulnerability is a stack overflow triggered via the list parameter within the fromSetIpMacBind function, which can be reached by an unauthenticated attacker over the network.

Business impact

The exploitation of this flaw results in a denial of service, rendering the affected network device unresponsive. Given the CVSS score of 7.5, this high severity issue poses a significant risk to operational continuity, as a successful attack could disrupt network connectivity for all users reliant on the affected hardware.

Remediation

Immediate Action: Since no patch is currently identified, users should restrict administrative access to the device interface to trusted management networks only.

Proactive Monitoring: Monitor system logs for unexpected crashes or service interruptions originating from the management interface.

Compensating Controls: Implement firewall rules to block unsolicited external access to the device web management interface.

Exploitation status

Public Exploit Available: Yes, a technical write-up containing attack details is available via the linked GitHub repository.

Analyst recommendation

While the current impact is limited to denial of service, the ability for an unauthenticated attacker to crash the device necessitates immediate containment. Administrators should prioritize isolating the management interface from the public internet and await further guidance or firmware updates from the vendor.

More Tenda CVEs

Sources