CVE-2025-14665: Tenda WH450 HTTP Request DhcpListClient stack-based overflow
A security flaw has been discovered in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/DhcpListClient of the component HTTP Request Handler. The manipulation of the argument page results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14665?
CVE-2025-14665 has a high severity due to its exploitation potential leading to remote code execution.
How do I fix CVE-2025-14665?
To fix CVE-2025-14665, update the Tenda WH450 firmware to the latest version provided by the vendor.
What components are affected by CVE-2025-14665?
CVE-2025-14665 affects the HTTP Request Handler component of Tenda WH450, specifically the function handling /goform/DhcpListClient.
Is CVE-2025-14665 exploitable remotely?
Yes, CVE-2025-14665 is exploitable remotely, allowing attackers to manipulate the system over the network.
What type of vulnerability is CVE-2025-14665?
CVE-2025-14665 is a stack-based buffer overflow vulnerability.