CVE-2025-11586: Tenda AC7 setNotUpgrade stack-based overflow
A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgrade. This manipulation of the argument newVersion causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11586?
CVE-2025-11586 is a high severity vulnerability due to its potential for remote exploitation and stack-based buffer overflow.
How do I fix CVE-2025-11586?
To fix CVE-2025-11586, it is recommended to update Tenda AC7 firmware to the latest version provided by the manufacturer.
What kind of attack can exploit CVE-2025-11586?
CVE-2025-11586 can be exploited through a remote attack that involves manipulating the 'newVersion' argument.
Which devices are affected by CVE-2025-11586?
CVE-2025-11586 affects the Tenda AC7 version 15.03.06.44.
Is CVE-2025-11586 being actively exploited in the wild?
Yes, CVE-2025-11586 has been reported to be publicly exploitable, increasing its risk to affected devices.