CVE-2025-60662
7.5Tenda · AC18
Tenda AC18 V15.03.05.19 contains a stack overflow vulnerability in the fromAdvSetMacMtuWan function triggered via the wanSpeed parameter.
Executive summary
A critical stack overflow vulnerability in Tenda AC18 firmware allows unauthenticated attackers to trigger a denial of service condition.
Vulnerability
This is a stack-based buffer overflow occurring within the fromAdvSetMacMtuWan function. The vulnerability is reachable by an unauthenticated attacker via the wanSpeed parameter, which lacks proper bounds checking.
Business impact
Successful exploitation of this vulnerability results in a denial of service, rendering the affected networking hardware unresponsive. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to network availability, potentially leading to business disruption if the device acts as a primary gateway or edge router.
Remediation
Immediate Action: Since a vendor-provided patch is currently unknown, administrators should restrict management interface access to trusted internal networks only. If possible, isolate the device from the public internet to prevent unauthenticated remote access to the vulnerable function.
Proactive Monitoring: Monitor device logs for abnormal crashes, unexpected reboots, or high CPU utilization associated with the management interface. Review ingress traffic patterns for malformed parameters directed at the device's configuration endpoints.
Compensating Controls: Implement a Web Application Firewall or similar network security appliance to inspect traffic and drop requests containing oversized payloads directed at the wanSpeed parameter.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The vulnerability represents a significant risk to the availability of Tenda AC18 hardware. Organizations utilizing this device must prioritize network segmentation to prevent external access to the management interface until a firmware update is released and applied. Monitor vendor channels closely for the availability of a patch to remediate this buffer overflow.