CVE-2025-12214: Tenda O3 sysAutoReboot GetValue stack-based overflow
A vulnerability was detected in Tenda O3 1.0.0.10(2478). This issue affects the function SetValue/GetValue of the file /goform/sysAutoReboot. Performing a manipulation of the argument enable results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12214?
CVE-2025-12214 has been classified as a high severity vulnerability due to its potential for remote exploitation and stack-based buffer overflow.
How do I fix CVE-2025-12214?
To mitigate CVE-2025-12214, users should update their Tenda O3 devices to the latest firmware version provided by the vendor.
What impact does CVE-2025-12214 have on Tenda O3 devices?
CVE-2025-12214 allows an attacker to perform remote manipulation of the device, potentially leading to unauthorized access and system instability.
Is CVE-2025-12214 exploitable remotely?
Yes, CVE-2025-12214 can be exploited remotely, allowing attackers to initiate an attack without physical access to the device.
What specific function is affected by CVE-2025-12214?
CVE-2025-12214 affects the SetValue/GetValue functions in the /goform/sysAutoReboot file.