nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-12618 CVE-2025-12618
HIGH
Tenda AC8 DatabaseIniSet buffer overflow
Record summary
CVE-2025-12618 has a selected CVSS score of 8.7 (high).
Description
A vulnerability has been found in Tenda AC8 16.03.34.06. This impacts an unknown function of the file /goform/DatabaseIniSet. The manipulation of the argument Time leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 3, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 16.03.34.06 | affected |
References
7pan.baidu.comexploit
https://pan.baidu.com/s/11fdpTujKw6Xz0yPE2l4cMw VDB-330912 | CTI Indicators (IOB, IOC, IOA)signaturepermissions required
https://vuldb.com/?ctiid.330912 VDB-330912 | Tenda AC8 DatabaseIniSet buffer overflowvdb entryTechnical description
https://vuldb.com/?id.330912 Submit #678887 | tenda AC8v4.0 V16.03.34.06 buffer overflowThird-party advisory
https://vuldb.com/?submit.678887 tenda.com.cnproduct
https://www.tenda.com.cn/ yuque.combroken link
https://www.yuque.com/ba1ma0-an29k/nnxoap/ow5xrpw56dqsgtdy?singleDoc