CVE-2025-12211: Tenda O3 setDmzInfo GetValue stack-based overflow
A security flaw has been discovered in Tenda O3 1.0.0.10(2478). Affected by this issue is the function SetValue/GetValue of the file /goform/setDmzInfo. The manipulation of the argument dmzIP results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12211?
CVE-2025-12211 has a high severity level due to its potential for remote exploitation via a stack-based buffer overflow.
How do I fix CVE-2025-12211?
To fix CVE-2025-12211, update the Tenda O3 device firmware to the latest version provided by the vendor.
What types of devices are impacted by CVE-2025-12211?
CVE-2025-12211 specifically affects Tenda O3 devices running version 1.0.0.10(2478).
Can CVE-2025-12211 be exploited remotely?
Yes, CVE-2025-12211 can be exploited remotely due to its stack-based buffer overflow vulnerability.
What are the potential consequences of CVE-2025-12211?
Exploitation of CVE-2025-12211 can lead to arbitrary code execution and potential unauthorized access to the device.