CVE-2025-29135

A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to execute arbitrary code through a stack overflow attack using the security parameter of the formWifiBasicSet function.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac7_firmware:15.03.06.44:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac7:1.0:*:*:*:*:*:*:*

History

01 Apr 2025, 19:58

Type Values Removed Values Added
First Time Tenda ac7
Tenda ac7 Firmware
Tenda
References () https://gist.github.com/Raining-101/1651dd3901efdbb38d94a156a54bbc62 - () https://gist.github.com/Raining-101/1651dd3901efdbb38d94a156a54bbc62 - Third Party Advisory
References () https://github.com/Raining-101/IOT_cve/blob/main/a7_formWifiBasic_Setsecurity_stackoverflow.md - () https://github.com/Raining-101/IOT_cve/blob/main/a7_formWifiBasic_Setsecurity_stackoverflow.md - Exploit
CPE cpe:2.3:o:tenda:ac7_firmware:15.03.06.44:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac7:1.0:*:*:*:*:*:*:*

26 Mar 2025, 15:16

Type Values Removed Values Added
References () https://github.com/Raining-101/IOT_cve/blob/main/a7_formWifiBasic_Setsecurity_stackoverflow.md - () https://github.com/Raining-101/IOT_cve/blob/main/a7_formWifiBasic_Setsecurity_stackoverflow.md -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-121
Summary
  • (es) Una vulnerabilidad de desbordamiento de búfer basada en pila en Tenda AC7 V15.03.06.44 permite a un atacante remoto ejecutar código arbitrario a través de un ataque de desbordamiento de pila utilizando el parámetro de seguridad de la función formWifiBasicSet.

24 Mar 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-24 21:15

Updated : 2025-04-01 19:58


NVD link : CVE-2025-29135

Mitre link : CVE-2025-29135

CVE.ORG link : CVE-2025-29135


JSON object : View

Products Affected

tenda

  • ac7
  • ac7_firmware
CWE
CWE-121

Stack-based Buffer Overflow