CVE-2025-9023

HIGH

Tenda Ac7 Firmware - Memory Corruption

Title source: rule
STIX 2.1

Description

A vulnerability has been found in Tenda AC7 and AC18 15.03.05.19/15.03.06.44. Affected is the function formSetSchedLed of the file /goform/SetLEDCfg. The manipulation of the argument Time leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.320088
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.320088
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.629692
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.629696
Product product
https://www.tenda.com.cn/

Scores

CVSS v3 8.8
EPSS 0.0046
EPSS Percentile 64.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-120
Status published
Products (2)
tenda/ac18_firmware 15.03.05.19
tenda/ac7_firmware 15.03.06.44
Published Aug 15, 2025
Tracked Since Feb 18, 2026