CVE-2025-14655: Tenda AC20 httpd SetSysAutoRebbotCfg formSetRebootTimer stack-based overflow
A security flaw has been discovered in Tenda AC20 16.03.08.12. The impacted element is the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd. Performing a manipulation of the argument rebootTime results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14655?
CVE-2025-14655 has a high severity rating due to the stack-based buffer overflow vulnerability that can be exploited by an attacker.
How do I fix CVE-2025-14655?
To fix CVE-2025-14655, update the Tenda AC20 to the latest firmware version that addresses this vulnerability.
What devices are affected by CVE-2025-14655?
The Tenda AC20 with firmware version 16.03.08.12 is affected by CVE-2025-14655.
What kind of attack does CVE-2025-14655 allow?
CVE-2025-14655 allows an attacker to exploit a stack-based buffer overflow through parameter manipulation in the reboot timer function.
Is CVE-2025-14655 being actively exploited?
At this time, there is no confirmed information on active exploitation of CVE-2025-14655, but users are advised to apply patches promptly.