First published: Thu Jan 30 2025(Updated: )
A vulnerability was found in Tenda A18 up to 15.13.07.09. It has been rated as critical. This issue affects the function SetCmdlineRun of the file /goform/SetCmdlineRun of the component HTTP POST Request Handler. The manipulation of the argument wpapsk_crypto5g leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda A18 Firmware | <=15.13.07.09 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0848 has been rated as critical due to its impact on system security.
To fix CVE-2025-0848, update the Tenda A18 to a version above 15.13.07.09.
CVE-2025-0848 affects the HTTP POST Request Handler function SetCmdlineRun.
Versions up to and including 15.13.07.09 of Tenda A18 are vulnerable to CVE-2025-0848.
CVE-2025-0848 is a stack-based buffer overflow vulnerability.