CVE-2025-11328: Tenda AC18 SetDDNSCfg stack-based overflow
A vulnerability was detected in Tenda AC18 15.03.05.19(6318). This issue affects some unknown processing of the file /goform/SetDDNSCfg. The manipulation of the argument ddnsEn results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11328?
CVE-2025-11328 is considered critical due to its potential for remote exploitation through a stack-based buffer overflow.
How do I fix CVE-2025-11328?
To mitigate CVE-2025-11328, update the Tenda AC18 firmware to the latest version provided by the manufacturer.
Who is affected by CVE-2025-11328?
CVE-2025-11328 affects users of the Tenda AC18 router running firmware version 15.03.05.19(6318).
Can CVE-2025-11328 be exploited remotely?
Yes, CVE-2025-11328 can be exploited remotely, allowing attackers to execute unauthorized commands.
What are the potential impacts of CVE-2025-11328?
If exploited, CVE-2025-11328 may allow attackers to execute arbitrary code, leading to a complete compromise of the device.