CVE-2025-70656

7.5

Tenda · AX-1806

A stack overflow vulnerability exists in the Tenda AX-1806 v1.0.0.1 router within the mac parameter of the sub_65B5C function, allowing unauthenticated attackers to cause a Denial of Service.

Executive summary

A stack overflow vulnerability in Tenda AX-1806 routers allows unauthenticated remote attackers to cause a Denial of Service via a crafted network request.

Vulnerability

This is a stack overflow vulnerability occurring in the mac parameter of the sub_65B5C function. The CVSS vector indicates this flaw is remotely exploitable by an unauthenticated attacker without requiring user interaction.

Business impact

The ability for an unauthenticated attacker to remotely trigger a Denial of Service poses a significant risk to network availability. Given the CVSS score of 7.5, this vulnerability is classified as High severity, as it can disrupt critical business communications and connectivity provided by the affected hardware.

Remediation

Immediate Action: As no official patch is currently identified, verify with Tenda support for available firmware updates addressing this stack overflow. If no update is available, restrict access to the device management interface from untrusted networks.

Proactive Monitoring: Monitor device uptime and system logs for unexpected reboots or service interruptions that may indicate exploitation attempts.

Compensating Controls: Implement network-level access controls to ensure the device is not reachable from the public internet, thereby preventing external exploitation of the vulnerable parameter.

Exploitation status

Public Exploit Available: Yes — a published proof-of-concept exists in the researcher write-up referenced by the CVE record.

Analyst recommendation

Due to the remote and unauthenticated nature of this vulnerability, immediate steps must be taken to isolate affected Tenda AX-1806 devices from the public internet. Organizations should prioritize restricting access to the management interface and contact the vendor regarding the availability of a firmware update to remediate the underlying stack overflow flaw.

More Tenda CVEs

Sources