CVE-2025-57638

7.5

Tenda · AC9

A buffer overflow vulnerability exists in Tenda AC9 version 1.0, which can be triggered via the user supplied sys.vendor configuration value.

Executive summary

A critical buffer overflow vulnerability in Tenda AC9 routers allows unauthenticated attackers to cause a denial of service condition.

Vulnerability

This is a buffer overflow vulnerability triggered by an unauthenticated attacker sending a malicious payload to the sys.vendor configuration parameter. The vulnerability allows for the disruption of service, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.

Business impact

Successful exploitation of this vulnerability results in a denial of service, rendering the affected networking hardware unresponsive. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to business continuity, particularly for remote offices or critical infrastructure relying on these routers for network connectivity.

Remediation

Immediate Action: Since no official patch is currently available, administrators should restrict access to the device management interface to trusted internal networks only.

Proactive Monitoring: Monitor network traffic and system logs for anomalous requests directed at configuration endpoints, specifically those targeting the sys.vendor parameter.

Compensating Controls: Implement strict firewall rules to prevent external access to the device administration interface, and ensure that only authorized personnel can communicate with the router management port.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the referenced security research documentation.

Analyst recommendation

Given the availability of a proof-of-concept and the lack of a vendor-provided patch, this vulnerability presents a credible risk to network availability. Organizations utilizing Tenda AC9 hardware must immediately isolate the management interface from the public internet to prevent exploitation. Continue to monitor the vendor support portal for firmware updates and apply them immediately upon release.

More Tenda CVEs

Sources