CVE-2025-11388: Tenda AC15 setNotUpgrade stack-based overflow
A vulnerability was identified in Tenda AC15 15.03.05.18. This impacts an unknown function of the file /goform/setNotUpgrade. Such manipulation of the argument newVersion leads to stack-based buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11388?
CVE-2025-11388 is classified as a high severity vulnerability due to its potential for remote execution and stack-based buffer overflow.
How do I fix CVE-2025-11388?
To fix CVE-2025-11388, update the Tenda AC15 firmware to the latest version released by Tenda that addresses this vulnerability.
What kind of attack can exploit CVE-2025-11388?
CVE-2025-11388 can be exploited through a remote attack that manipulates the newVersion argument in the affected file to achieve a buffer overflow.
Is there a known public exploit for CVE-2025-11388?
Yes, there is a publicly available exploit for CVE-2025-11388, which highlights the urgency of addressing this vulnerability.
What happens if CVE-2025-11388 is exploited?
If CVE-2025-11388 is exploited, an attacker may gain unauthorized access to the system, potentially leading to further compromise.