CVE-2025-15008: Tenda WH450 HTTP Request L7Port stack-based overflow
A vulnerability was detected in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/L7Port of the component HTTP Request Handler. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15008?
CVE-2025-15008 is classified as a high severity vulnerability due to the potential for remote exploitation and stack-based buffer overflow.
How do I fix CVE-2025-15008?
To fix CVE-2025-15008, update the Tenda WH450 firmware to the latest version provided by the vendor.
Who is affected by CVE-2025-15008?
CVE-2025-15008 affects the Tenda WH450 version 1.0.0.18 for users relying on its HTTP request handling capabilities.
Can CVE-2025-15008 be exploited remotely?
Yes, CVE-2025-15008 can be exploited remotely, allowing attackers to perform unauthorized manipulations.
What component is vulnerable in CVE-2025-15008?
The vulnerability in CVE-2025-15008 is present in the HTTP Request Handler component, specifically related to the /goform/L7Port file.