CVE-2025-12213: Tenda O3 setVlanConfig GetValue stack-based overflow
A security vulnerability has been detected in Tenda O3 1.0.0.10(2478). This vulnerability affects the function SetValue/GetValue of the file /goform/setVlanConfig. Such manipulation of the argument lan leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12213?
CVE-2025-12213 has been classified as a high-severity vulnerability due to the potential for remote exploitation and stack-based buffer overflow.
How do I fix CVE-2025-12213?
To fix CVE-2025-12213, update the Tenda O3 firmware to the latest version that addresses this vulnerability.
Which versions of Tenda O3 are affected by CVE-2025-12213?
CVE-2025-12213 affects Tenda O3 version 1.0.0.10(2478) and possibly other versions that have not been updated.
Can CVE-2025-12213 be exploited remotely?
Yes, CVE-2025-12213 can be exploited remotely, allowing attackers to manipulate the vulnerable function from outside the network.
What are the potential consequences of exploiting CVE-2025-12213?
Exploiting CVE-2025-12213 may lead to unauthorized access, system crashes, or arbitrary code execution on the affected device.