CVE-2025-61498

7.5

Tenda · AC8 Hardware v03

A buffer overflow in the Tenda AC8 UPnP service allows an unauthenticated remote attacker to trigger a Denial of Service condition via a specially crafted packet.

Executive summary

A buffer overflow vulnerability in the Tenda AC8 router allows unauthenticated remote attackers to crash the device, resulting in a Denial of Service.

Vulnerability

This is a buffer overflow vulnerability within the Universal Plug and Play (UPnP) service. The flaw can be triggered by an unauthenticated attacker sending a crafted network packet to the vulnerable service.

Business impact

The vulnerability carries a CVSS score of 7.5, which indicates a High severity risk primarily due to the potential for service disruption. Successful exploitation results in a Denial of Service, which can lead to significant network downtime, loss of connectivity for dependent business operations, and the need for manual device resets.

Remediation

Immediate Action: Since a patch is currently unknown, users should immediately disable the UPnP service on the affected Tenda AC8 hardware via the web management interface to eliminate the attack vector.

Proactive Monitoring: Monitor network traffic for unusual patterns directed at the UPnP service port and review system logs for recurring service crashes or unexpected reboots.

Compensating Controls: Implement network segmentation to isolate the management interface and UPnP-enabled services from public-facing segments, effectively restricting the attack surface.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as documented in the research repository referenced in the CVE record.

Analyst recommendation

Given the High severity of this flaw and the ease of exploitation, administrators should prioritize disabling the UPnP feature on all identified Tenda AC8 units. If the service is required, ensure the device is behind a robust firewall that blocks unauthorized access to the UPnP port until a vendor patch is released and applied.

More Tenda CVEs

Sources