CVE-2025-11325: Tenda AC18 fast_setting_pppoe_set stack-based overflow
A security flaw has been discovered in Tenda AC18 15.03.05.19(6318). Affected by this issue is some unknown functionality of the file /goform/fastsettingpppoeset. Performing a manipulation of the argument Username results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11325?
CVE-2025-11325 has been classified as a high-severity vulnerability due to the potential for exploitation via stack-based buffer overflow.
How do I fix CVE-2025-11325?
To mitigate CVE-2025-11325, update the Tenda AC18 firmware to the latest version that addresses this vulnerability.
What is the impact of CVE-2025-11325?
The impact of CVE-2025-11325 may allow an attacker to execute arbitrary code on the affected device, potentially leading to unauthorized access.
Which devices are affected by CVE-2025-11325?
CVE-2025-11325 affects the Tenda AC18 router running firmware version 15.03.05.19(6318).
Is CVE-2025-11325 easily exploitable?
Yes, CVE-2025-11325 is considered easily exploitable due to its reliance on manipulating a parameter within unsecured functionality.