CVE-2025-11122: Tenda AC18 WizardHandle stack-based overflow
A vulnerability was detected in Tenda AC18 15.03.05.19. This affects an unknown function of the file /goform/WizardHandle. The manipulation of the argument WANT/mtuvalue results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11122?
CVE-2025-11122 has a high severity rating due to its potential for remote exploitation and the stack-based buffer overflow it causes.
How do I fix CVE-2025-11122?
To fix CVE-2025-11122, update the Tenda AC18 firmware to the latest version where this vulnerability has been addressed.
Who is affected by CVE-2025-11122?
CVE-2025-11122 affects users of the Tenda AC18 router running on firmware version 15.03.05.19.
Can CVE-2025-11122 be exploited remotely?
Yes, CVE-2025-11122 can be exploited remotely, allowing attackers to initiate an attack without physical access to the device.
What impact does CVE-2025-11122 have on the affected system?
The impact of CVE-2025-11122 includes the potential for an attacker to execute arbitrary code on the affected Tenda AC18 device.