CVE-2025-70650
7.5Tenda · AX-1806
A stack overflow vulnerability in the Tenda AX-1806 router allows unauthenticated remote attackers to cause a denial of service via a crafted request to the deviceList parameter.
Executive summary
A critical stack overflow vulnerability in Tenda AX-1806 routers permits unauthenticated remote attackers to crash the device and cause a denial of service.
Vulnerability
The device is susceptible to a stack overflow within the deviceList parameter of the formSetMacFilterCfg function. This flaw can be triggered by an unauthenticated attacker sending a specifically crafted network request to the device.
Business impact
Successful exploitation of this vulnerability results in a denial of service, rendering the affected networking hardware unresponsive. Given the CVSS score of 7.5, this high severity risk could lead to significant operational disruption for users relying on the device for network connectivity. Such outages can halt business processes and require manual intervention to restore device functionality.
Remediation
Immediate Action: Since no official vendor patch is currently confirmed, administrators should restrict management interface access to trusted IP addresses only and disable remote management features if they are not strictly required.
Proactive Monitoring: Monitor device logs for repetitive, malformed requests targeting the administrative configuration endpoints or sudden, unexplained device reboots.
Compensating Controls: Deploy a network firewall or an intrusion prevention system to filter and block traffic directed at the web management interface of the Tenda device.
Exploitation status
Public Exploit Available: Yes — a published proof-of-concept exists, as documented in the technical write-up referenced by the CVE record.
Analyst recommendation
Due to the availability of a proof-of-concept and the potential for remote denial of service, this vulnerability presents a credible risk to network availability. Organizations utilizing the Tenda AX-1806 must prioritize limiting exposure by isolating the device management interface from untrusted networks until the vendor releases a formal security update.