CVE-2025-15046: Tenda WH450 HTTP Request PPTPClient stack-based overflow
A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/PPTPClient of the component HTTP Request Handler. Such manipulation of the argument netmsk leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15046?
CVE-2025-15046 is classified as a high severity vulnerability due to the potential for stack-based buffer overflow exploitation.
How do I fix CVE-2025-15046?
To fix CVE-2025-15046, ensure you apply the latest firmware updates provided by Tenda for the WH450 model.
What impact does CVE-2025-15046 have on my device?
CVE-2025-15046 can lead to unauthorized access and potentially allow attackers to execute arbitrary code on your Tenda WH450 device.
Is CVE-2025-15046 remotely exploitable?
Yes, CVE-2025-15046 can be remotely exploited through manipulation of HTTP requests targeting the PPTPClient functionality.
Are there any known attacks leveraging CVE-2025-15046?
As of now, there are no publicly reported attacks specifically leveraging CVE-2025-15046, but the vulnerability poses significant risk.