CVE-2025-70645
7.5Tenda · AX-1806
A stack overflow vulnerability in the Tenda AX-1806 router allows unauthenticated remote attackers to cause a denial of service via a crafted request to the formSetWifiMacFilterCfg function.
Executive summary
A stack overflow vulnerability in Tenda AX-1806 devices permits unauthenticated remote attackers to trigger a denial of service condition.
Vulnerability
This is a stack-based buffer overflow occurring within the deviceList parameter of the formSetWifiMacFilterCfg function. The vulnerability is exploitable by unauthenticated remote attackers over the network.
Business impact
The exploitation of this vulnerability results in a denial of service, which renders the network device unresponsive and disrupts connectivity for all users reliant on the affected hardware. Given the CVSS score of 7.5, this high-severity flaw poses a significant operational risk to business continuity, particularly in environments where uptime is critical. An attacker can trigger this state remotely without any prior authentication, making it a viable target for disruptive attacks.
Remediation
Immediate Action: Since no official patch is currently available, administrators should restrict management interface access to trusted internal networks only.
Proactive Monitoring: Monitor device logs for unusual traffic patterns or repeated requests directed at the WiFi configuration interface that may indicate probing for this overflow.
Compensating Controls: Deploy a firewall rule or Intrusion Prevention System (IPS) signature designed to inspect and drop malformed requests containing oversized payloads in the deviceList parameter.
Exploitation status
Public Exploit Available: Yes — a published proof-of-concept exists, attributed to the research write-up referenced in the CVE record.
Analyst recommendation
Due to the remote and unauthenticated nature of this vulnerability, Tenda AX-1806 users should prioritize limiting the exposure of the administrative interface to the public internet. While a vendor patch is pending, applying network-level segmentation or access control lists is necessary to mitigate the risk of remote denial of service attacks. Monitor vendor channels closely for the release of a firmware update that addresses the stack overflow.