CVE-2025-70644

7.5

Tenda · AX-1806

A stack overflow vulnerability exists in the time parameter of the sub_60CFC function in Tenda AX-1806 version 1.0.0.1, allowing unauthenticated attackers to cause a Denial of Service.

Executive summary

A stack overflow vulnerability in Tenda AX-1806 allows unauthenticated remote attackers to trigger a Denial of Service condition on the affected device.

Vulnerability

The vulnerability is a stack-based buffer overflow located in the time parameter of the sub_60CFC function, which can be triggered by an unauthenticated attacker via a crafted request.

Business impact

Successful exploitation of this vulnerability results in a Denial of Service (DoS), rendering the affected networking hardware unresponsive. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to network availability, potentially disrupting business operations that rely on the connectivity provided by the Tenda device.

Remediation

Immediate Action: Since no vendor patch is currently confirmed, administrators should restrict access to the device management interface from untrusted networks and segment the device from public-facing internet traffic.

Proactive Monitoring: Monitor system logs for repeated crashes or unusual request patterns directed at the device management interface.

Compensating Controls: Deploy a network firewall or Web Application Firewall (WAF) to filter inbound traffic and block malformed requests targeting device parameters.

Exploitation status

Public Exploit Available: Yes — a public proof-of-concept exists as documented in the research write-up referenced by the CVE record.

Analyst recommendation

The vulnerability represents a significant risk to network stability due to its remote, unauthenticated exploitability. Organizations currently deploying the Tenda AX-1806 should prioritize isolating these devices from external access and monitor vendor channels for the release of an official firmware update to address the buffer overflow flaw.

More Tenda CVEs

Sources