CVE-2025-15047: Tenda WH450 HTTP Request PPTPDClient stack-based overflow
A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of the component HTTP Request Handler. Performing a manipulation of the argument Username results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15047?
CVE-2025-15047 is classified as a high-severity vulnerability due to its potential for remote exploitation through stack-based buffer overflow.
How do I fix CVE-2025-15047?
To fix CVE-2025-15047, update the Tenda WH450 firmware to the latest version that addresses this vulnerability.
What type of attack can exploit CVE-2025-15047?
CVE-2025-15047 can be exploited through a remote attack targeting the HTTP Request Handler in the Tenda WH450.
Which devices are affected by CVE-2025-15047?
CVE-2025-15047 affects Tenda WH450 devices running firmware version 1.0.0.18.
What is the impact of CVE-2025-15047?
The impact of CVE-2025-15047 includes potential unauthorized access to the system due to stack-based buffer overflow vulnerabilities.