CVE-2025-70747

7.5

Tenda · AX-1806

A stack overflow vulnerability in the Tenda AX-1806 router allows unauthenticated remote attackers to trigger a denial of service via a crafted request to the serviceName parameter.

Executive summary

The Tenda AX-1806 router is vulnerable to a stack overflow flaw that allows unauthenticated attackers to crash the device.

Vulnerability

The device contains a stack overflow vulnerability within the serviceName parameter of the sub_65A28 function. This flaw is exploitable by an unauthenticated attacker sending a specifically crafted network request.

Business impact

The exploitation of this vulnerability results in a Denial of Service (DoS) condition, rendering the router unresponsive. Given the CVSS score of 7.5 (High), this represents a significant risk to operational continuity for businesses relying on this hardware for network connectivity. An attacker can remotely disrupt critical communications without requiring any prior authentication or user interaction.

Remediation

Immediate Action: Since a vendor patch is currently unknown, administrators should restrict management interface access to trusted IP addresses and disable remote management features where possible.

Proactive Monitoring: Monitor network traffic for unusual or oversized packets directed at the router management services and review device logs for frequent, unexplained service restarts.

Compensating Controls: Implement a perimeter firewall to block unauthorized access to the router management interface from the public internet, effectively isolating the vulnerable function from external reach.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists, attributed to the technical write-up provided in the vulnerability references.

Analyst recommendation

The severity of this issue is heightened by the lack of required authentication and the existence of a public proof-of-concept. Organizations utilizing the Tenda AX-1806 should treat this as a high priority and enforce strict network segmentation to prevent external access to the device until the vendor releases a security update.

More Tenda CVEs

Sources