CVE-2025-15356: Tenda AC20 PowerSaveSet sscanf buffer overflow
A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The impacted element is the function sscanf of the file /goform/PowerSaveSet. The manipulation of the argument powerSavingEn/time/powerSaveDelay/ledCloseType leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15356?
CVE-2025-15356 is classified as a critical severity vulnerability due to the potential for remote code execution through buffer overflow.
How do I fix CVE-2025-15356?
To fix CVE-2025-15356, update your Tenda AC20 router firmware to a version newer than 16.03.08.12.
What is affected by CVE-2025-15356?
CVE-2025-15356 affects Tenda AC20 versions up to and including 16.03.08.12.
Can CVE-2025-15356 be exploited remotely?
Yes, CVE-2025-15356 can be exploited remotely by manipulating specific parameters in the PowerSaveSet function.
What does CVE-2025-15356 involve?
CVE-2025-15356 involves a buffer overflow vulnerability caused by improper handling of parameters in the sscanf function.