CVE-2025-71021
7.5Tenda · AX-1806
A stack overflow vulnerability in the serverName parameter of the Tenda AX-1806 router allows unauthenticated attackers to trigger a denial of service condition via a crafted network request.
Executive summary
A stack overflow vulnerability in the Tenda AX-1806 router enables unauthenticated remote attackers to crash the device, resulting in a denial of service.
Vulnerability
This is a stack-based buffer overflow vulnerability located in the serverName parameter of the sub_65A28 function. The flaw is reachable by unauthenticated attackers, allowing them to send malicious input that triggers a service crash.
Business impact
The vulnerability poses a significant risk to network availability, as a successful exploit will cause the device to crash or become unresponsive. Given the CVSS score of 7.5, this high-severity flaw could lead to operational disruption for organizations relying on this hardware for connectivity, necessitating prompt attention despite the current lack of a confirmed vendor patch.
Remediation
Immediate Action: Since no official patch is currently available, restrict management access to the router to trusted internal networks only and disable remote administration features if they are not strictly required.
Proactive Monitoring: Monitor device uptime logs and network traffic for unusual spikes or repetitive malformed requests directed at administrative endpoints.
Compensating Controls: Deploy a network firewall or intrusion prevention system to filter traffic and block malformed packets targeting known administrative parameters on the device.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical write-up provided by the researcher on GitHub.
Analyst recommendation
Organizations utilizing Tenda AX-1806 units should treat this vulnerability with high priority due to the ease of exploitation. While waiting for a vendor-supplied firmware update, administrators must implement network-level access controls to isolate the device from the public internet. Continued monitoring of vendor support channels is essential to ensure the patch is applied as soon as it becomes available.