CVE-2025-7434

A vulnerability was found in Tenda FH451 up to 1.0.0.9 and classified as critical. Affected by this issue is the function fromAddressNat of the file /goform/addressNat of the component POST Request Handler. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:fh451_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh451:-:*:*:*:*:*:*:*

History

16 Jul 2025, 16:43

Type Values Removed Values Added
References () https://github.com/zezhifu1/cve_report/blob/main/FH451/fromAddressNat.md - () https://github.com/zezhifu1/cve_report/blob/main/FH451/fromAddressNat.md - Exploit, Third Party Advisory
References () https://github.com/zezhifu1/cve_report/blob/main/FH451/fromAddressNat.md#payload - () https://github.com/zezhifu1/cve_report/blob/main/FH451/fromAddressNat.md#payload - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.316004 - () https://vuldb.com/?ctiid.316004 - Permissions Required
References () https://vuldb.com/?id.316004 - () https://vuldb.com/?id.316004 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.609058 - () https://vuldb.com/?submit.609058 - Third Party Advisory, VDB Entry
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product
First Time Tenda
Tenda fh451 Firmware
Tenda fh451
CPE cpe:2.3:o:tenda:fh451_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh451:-:*:*:*:*:*:*:*

11 Jul 2025, 14:15

Type Values Removed Values Added
References () https://github.com/zezhifu1/cve_report/blob/main/FH451/fromAddressNat.md - () https://github.com/zezhifu1/cve_report/blob/main/FH451/fromAddressNat.md -
Summary
  • (es) Se detectó una vulnerabilidad en Tenda FH451 hasta la versión 1.0.0.9, clasificada como crítica. Este problema afecta la función fromAddressNat del archivo /goform/addressNat del componente POST Request Handler. La manipulación de la página de argumentos provoca un desbordamiento del búfer en la pila. El ataque puede ejecutarse en remoto. Se ha hecho público el exploit y puede que sea utilizado.

11 Jul 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-11 02:15

Updated : 2025-07-16 16:43


NVD link : CVE-2025-7434

Mitre link : CVE-2025-7434

CVE.ORG link : CVE-2025-7434


JSON object : View

Products Affected

tenda

  • fh451_firmware
  • fh451
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow