CVE-2025-12611: Tenda AC21 SetPptpServerCfg formSetPPTPServer buffer overflow
A vulnerability was identified in Tenda AC21 16.03.08.16. This vulnerability affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIp leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12611?
CVE-2025-12611 is considered to be of high severity due to the potential for remote exploitation and its ability to cause a buffer overflow.
How do I fix CVE-2025-12611?
To fix CVE-2025-12611, it is recommended to update the Tenda AC21 firmware to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2025-12611?
CVE-2025-12611 is categorized as a buffer overflow vulnerability affecting the Tenda AC21 router.
Can CVE-2025-12611 be exploited remotely?
Yes, CVE-2025-12611 can be exploited remotely, allowing attackers to manipulate the startIp argument.
Which product is affected by CVE-2025-12611?
CVE-2025-12611 specifically affects the Tenda AC21 router.