CVE-2025-14654: Tenda AC20 httpd setPptpUserList formSetPPTPUserList stack-based overflow
A vulnerability was identified in Tenda AC20 16.03.08.12. The affected element is the function formSetPPTPUserList of the file /goform/setPptpUserList of the component httpd. Such manipulation of the argument list leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14654?
CVE-2025-14654 is considered a high severity vulnerability due to its potential for remote exploitation and the risk of stack-based buffer overflow.
How do I fix CVE-2025-14654?
To fix CVE-2025-14654, update the Tenda AC20 firmware to the latest version provided by Tenda that addresses this vulnerability.
What type of vulnerability is CVE-2025-14654?
CVE-2025-14654 is classified as a stack-based buffer overflow vulnerability in the affected component.
What is affected by CVE-2025-14654?
CVE-2025-14654 affects the Tenda AC20 router, particularly the formSetPPTPUserList function within its HTTP daemon.
Can CVE-2025-14654 be exploited remotely?
Yes, CVE-2025-14654 can be exploited remotely, allowing an attacker to manipulate the argument list leading to a potential stack overflow.