CVE-2025-11527: Tenda AC7 fast_setting_pppoe_set stack-based overflow
A vulnerability was determined in Tenda AC7 15.03.06.44. The impacted element is an unknown function of the file /goform/fastsettingpppoeset. Executing a manipulation of the argument Password can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11527?
The severity of CVE-2025-11527 is considered high due to the potential for remote exploitation and stack-based buffer overflow.
How do I fix CVE-2025-11527?
To fix CVE-2025-11527, update the Tenda AC7 firmware to the latest version provided by the vendor.
Who is affected by CVE-2025-11527?
CVE-2025-11527 affects users of the Tenda AC7 router specifically with the firmware version 15.03.06.44.
What can an attacker achieve with CVE-2025-11527?
An attacker can exploit CVE-2025-11527 to perform remote code execution through a buffer overflow via manipulated password arguments.
Is CVE-2025-11527 a local or remote vulnerability?
CVE-2025-11527 is a remote vulnerability that can be exploited without physical access to the affected device.