CVE-2025-60660

7.5

Tenda · AC18

A stack overflow vulnerability in the Tenda AC18 router allows for denial of service via the mac parameter in the fromAdvSetMacMtuWan function.

Executive summary

A critical stack overflow vulnerability in Tenda AC18 routers could allow an unauthenticated attacker to cause a denial of service condition.

Vulnerability

This vulnerability is a stack-based buffer overflow triggered by sending a specially crafted value to the mac parameter within the fromAdvSetMacMtuWan function. The attack can be executed by an unauthenticated user over the network.

Business impact

Successful exploitation of this vulnerability results in a denial of service, rendering the affected network device unresponsive. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to business continuity, as compromised routing equipment can disrupt all internal and external network traffic, leading to operational downtime.

Remediation

Immediate Action: Since a specific patch version is not currently listed, administrators should contact Tenda support for firmware updates or restrict access to the device management interface from untrusted networks.

Proactive Monitoring: Monitor device logs for recurring crashes or unexpected restarts that may indicate attempted exploitation of the stack overflow.

Compensating Controls: Implement firewall rules to restrict access to the device management interface, ensuring that only authorized administrative IP addresses can reach the affected service.

Exploitation status

Public Exploit Available: No (Exploit available: false)

Analyst recommendation

The vulnerability presents a credible risk of service disruption for Tenda AC18 users. Organizations should prioritize isolating the affected hardware from the public internet and await official vendor guidance on a permanent firmware update to resolve the buffer overflow.

More Tenda CVEs

Sources