CVE-2025-70646

7.5

Tenda · AX1803

Tenda AX1803 version 1.0.0.1 contains a stack overflow vulnerability in the sub_72290 function, which allows an unauthenticated attacker to trigger a denial of service via a crafted network request.

Executive summary

A critical stack overflow vulnerability in Tenda AX1803 firmware exposes the device to unauthenticated denial of service attacks.

Vulnerability

This is a stack overflow vulnerability located in the security parameter of the sub_72290 function. The flaw is reachable by an unauthenticated attacker, allowing them to crash the device through a specially crafted request.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity risk due to the ease of exploitation. Successful exploitation results in device downtime, which can disrupt network connectivity and impact operational continuity for users relying on the hardware for critical communications or data access.

Remediation

Immediate Action: Contact the vendor for firmware update availability and apply any issued security patches immediately to address the stack overflow condition.

Proactive Monitoring: Monitor device logs for anomalous traffic patterns or unexpected service restarts that may indicate attempted exploitation of this buffer overflow flaw.

Compensating Controls: Restrict management interface access to trusted administrative IP addresses and employ network segmentation to minimize exposure of the affected device to untrusted network segments.

Exploitation status

Public Exploit Available: Yes, a public proof of concept is available via the technical write-up published on GitHub.

Analyst recommendation

Given the high CVSS score and the existence of a public proof of concept, this vulnerability poses a significant risk to network stability. Administrators should prioritize the mitigation of this flaw by limiting network exposure and applying vendor-provided updates as soon as they become available.

More Tenda CVEs

Sources