CVE-2025-12209: Tenda O3 setDhcpConfig GetValue stack-based overflow
A vulnerability was determined in Tenda O3 1.0.0.10(2478). Affected is the function SetValue/GetValue of the file /goform/setDhcpConfig. Executing a manipulation of the argument dhcpEn can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12209?
CVE-2025-12209 is classified as a high severity vulnerability due to the potential for a stack-based buffer overflow.
How do I fix CVE-2025-12209?
To fix CVE-2025-12209, update the Tenda O3 device firmware to the latest version provided by the manufacturer.
What impact does CVE-2025-12209 have on Tenda O3 devices?
CVE-2025-12209 can enable remote attackers to exploit a buffer overflow, potentially allowing them to execute arbitrary code.
Is CVE-2025-12209 exploitable remotely?
Yes, CVE-2025-12209 can be exploited remotely without requiring physical access to the device.
What software versions are affected by CVE-2025-12209?
CVE-2025-12209 affects Tenda O3 version 1.0.0.10(2478) specifically.