CVE-2025-11327: Tenda AC18 SetUpnpCfg stack-based overflow
A security vulnerability has been detected in Tenda AC18 15.03.05.19(6318). This vulnerability affects unknown code of the file /goform/SetUpnpCfg. The manipulation of the argument upnpEn leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11327?
CVE-2025-11327 has a critical severity due to its potential for remote exploitation and stack-based buffer overflow.
How do I fix CVE-2025-11327?
To fix CVE-2025-11327, update the Tenda AC18 firmware to the latest version provided by the vendor.
What systems are affected by CVE-2025-11327?
CVE-2025-11327 specifically affects Tenda AC18 routers running the firmware version 15.03.05.19(6318).
What type of vulnerability is CVE-2025-11327?
CVE-2025-11327 is a stack-based buffer overflow vulnerability that can be exploited remotely.
Can CVE-2025-11327 be exploited remotely?
Yes, CVE-2025-11327 can be exploited remotely by manipulating the upnpEn argument in the affected file.