CVE Details
Basic Information
| Title | Tenda AC18 SetSysAutoRebbotCfg formsetreboottimer buffer overflow |
|---|---|
| Type | cve |
| Published | 2025-06-04T20:00:21.750Z |
| Last Seen |
Product Information
| Vendor | Tenda |
|---|---|
| Product | AC18 |
| Version | 15.03.05.05 |
CVSS Information
| Base Score | 8.7 (HIGH) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A critical buffer overflow vulnerability in Tenda AC18 routers allows remote attackers to exploit the formsetreboottimer function, potentially leading to system compromise. |
|---|---|
| AI Severity | High |
| Vendor | Tenda |
| Product | AC18 |
| Affected Version | 15.03.05.05 |
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-120, CWE-119 |
| Bulletin Family | |
| Source Data | Tenda AC18 15.03.05.05 |
Source Information
| Source Data | Tenda AC18 15.03.05.05 |
|---|---|
| Source Link |
Description
A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formsetreboottimer of the file /goform/SetSysAutoRebbotCfg. The manipulation of the argument rebootTime leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS Score Summary
Base Score: 8.7 (HIGH)