CVE-2025-11385: Tenda AC20 fast_setting_wifi_set sscanf buffer overflow
A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The affected element is the function sscanf of the file /goform/fastsettingwifiset. The manipulation of the argument timeZone leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11385?
CVE-2025-11385 has been assessed as a high severity vulnerability due to the potential for remote exploitation leading to a buffer overflow.
How do I fix CVE-2025-11385?
To fix CVE-2025-11385, update the Tenda AC20 firmware to a version newer than 16.03.08.12.
What is the impact of CVE-2025-11385?
CVE-2025-11385 can allow an attacker to exploit a buffer overflow vulnerability remotely, which may lead to arbitrary code execution.
Who is affected by CVE-2025-11385?
CVE-2025-11385 affects users of the Tenda AC20 router running firmware versions up to 16.03.08.12.
Can CVE-2025-11385 be exploited from outside the network?
Yes, CVE-2025-11385 can be exploited remotely, meaning an attacker does not need to be on the same local network.