CVE-2025-60663

7.5

Tenda · AC18

Tenda AC18 firmware version V15.03.05.19 is vulnerable to a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan function.

Executive summary

A critical stack overflow vulnerability in the Tenda AC18 router allows unauthenticated attackers to trigger a denial of service condition.

Vulnerability

This vulnerability is a stack-based buffer overflow occurring within the fromAdvSetMacMtuWan function. An unauthenticated attacker can trigger this condition by sending a specially crafted request containing a malicious wanMTU parameter.

Business impact

The exploitation of this vulnerability leads to a denial of service condition, which can cause significant network downtime and service disruption for businesses relying on these devices. Given the CVSS score of 7.5, the risk to service availability is high. Such interruptions can disrupt critical business operations and require manual device reboots to restore connectivity.

Remediation

Immediate Action: Since a patch is currently unknown, restrict administrative access to the device management interface to trusted internal networks only. Ensure the device is not directly exposed to the public internet to prevent remote exploitation.

Proactive Monitoring: Monitor device logs for abnormal traffic patterns or unexpected crashes related to network configuration requests. Review firewall logs for incoming traffic targeting management ports or unconventional MTU configuration attempts.

Compensating Controls: Implement an upstream firewall or Access Control List (ACL) to block unauthorized access to the router's management interface. Use a Web Application Firewall (WAF) if the device is exposed, though hardware-level restrictions are preferred for embedded router vulnerabilities.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing the Tenda AC18 router should prioritize network segmentation to isolate these devices from the public internet. Because a vendor patch is not currently confirmed, proactive perimeter defense and internal access restrictions are the most effective means to mitigate the risk of denial of service attacks. Monitor vendor communications closely for the release of an official firmware update.

More Tenda CVEs

Sources