CVE-2025-14995: Tenda FH1201 SetIpBind sprintf stack-based overflow
A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIpBind. Such manipulation of the argument page leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14995?
CVE-2025-14995 has a high severity rating due to its potential for a stack-based buffer overflow that can be exploited remotely.
How do I fix CVE-2025-14995?
To fix CVE-2025-14995, update the Tenda FH1201 to the latest firmware version provided by Tenda.
What types of attacks can exploit CVE-2025-14995?
CVE-2025-14995 can be exploited through remote buffer overflow attacks that manipulate the sprintf function in the affected software.
Which devices are affected by CVE-2025-14995?
CVE-2025-14995 specifically affects the Tenda FH1201 router running version 1.2.0.14(408).
Can CVE-2025-14995 be exploited without local access?
Yes, CVE-2025-14995 can be exploited remotely, allowing attackers to exploit the vulnerability without physical access to the device.