CVE-2025-14993: Tenda AC18 HTTP Request SetDlnaCfg sprintf stack-based overflow
A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg of the component HTTP Request Handler. The manipulation of the argument scanList results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14993?
CVE-2025-14993 has a high severity due to its potential for remote exploitation and causing stack-based buffer overflow.
How do I fix CVE-2025-14993?
To mitigate CVE-2025-14993, update the Tenda AC18 firmware to the latest version provided by the vendor.
What systems are affected by CVE-2025-14993?
CVE-2025-14993 affects the Tenda AC18 router running firmware version 15.03.05.05.
Can CVE-2025-14993 be exploited remotely?
Yes, CVE-2025-14993 can be exploited remotely if the attacker sends crafted HTTP requests to the affected device.
What type of vulnerability is CVE-2025-14993?
CVE-2025-14993 is a stack-based buffer overflow vulnerability in the HTTP Request Handler of the Tenda AC18.