A vulnerability classified as critical has been found in Tenda AX1803 1.0.0.1. Affected is the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/panda666-888/vuls/blob/main/tenda/ax1803/formSetMacFilterCfg.md | Exploit Third Party Advisory | 
| https://github.com/panda666-888/vuls/blob/main/tenda/ax1803/formSetMacFilterCfg.md#poc | Exploit Third Party Advisory | 
| https://vuldb.com/?ctiid.316296 | Permissions Required VDB Entry | 
| https://vuldb.com/?id.316296 | Third Party Advisory VDB Entry | 
| https://vuldb.com/?submit.615268 | Third Party Advisory VDB Entry | 
| https://www.tenda.com.cn/ | Product | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
History
                    15 Jul 2025, 18:27
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/panda666-888/vuls/blob/main/tenda/ax1803/formSetMacFilterCfg.md - Exploit, Third Party Advisory | |
| References | () https://github.com/panda666-888/vuls/blob/main/tenda/ax1803/formSetMacFilterCfg.md#poc - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/?ctiid.316296 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.316296 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.615268 - Third Party Advisory, VDB Entry | |
| References | () https://www.tenda.com.cn/ - Product | |
| CPE | cpe:2.3:h:tenda:ax1803:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:ax1803_firmware:1.0.0.1:*:*:*:*:*:*:*  | 
|
| First Time | 
        
        Tenda ax1803 Firmware
         Tenda Tenda ax1803  | 
14 Jul 2025, 11:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-07-14 11:15
Updated : 2025-07-15 18:27
NVD link : CVE-2025-7597
Mitre link : CVE-2025-7597
CVE.ORG link : CVE-2025-7597
JSON object : View
Products Affected
                tenda
- ax1803_firmware
 - ax1803
 
