CVE-2025-12225: Tenda AC6 HTTP Request WifiGuestSet stack-based overflow
A vulnerability has been found in Tenda AC6 15.03.06.50. This issue affects some unknown processing of the file /goform/WifiGuestSet of the component HTTP Request Handler. Such manipulation of the argument shareSpeed leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12225?
CVE-2025-12225 is considered a high-severity vulnerability due to the potential for stack-based buffer overflow.
How do I fix CVE-2025-12225?
To fix CVE-2025-12225, it is recommended to update the Tenda AC6 firmware to the latest version provided by the manufacturer.
What components are affected by CVE-2025-12225?
CVE-2025-12225 affects the HTTP Request Handler, specifically the /goform/WifiGuestSet file.
What type of vulnerability is CVE-2025-12225?
CVE-2025-12225 is classified as a stack-based buffer overflow vulnerability.
Can CVE-2025-12225 be remotely exploited?
Yes, CVE-2025-12225 can potentially be exploited remotely, allowing attackers to manipulate the shareSpeed argument.