CVE-2025-1814: Tenda AC6 WifiExtraSet stack-based overflow
Published Mar 2, 2025
·Updated
A vulnerability, which was classified as critical, has been found in Tenda AC6 15.03.05.16. Affected by this issue is some unknown functionality of the file /goform/WifiExtraSet. The manipulation of the argument wpapskcrypto leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda AC6
All of the following
Tenda Ac6 Firmware=15.03.05.16
Tenda AC6
Event History
Mar 2, 2025
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-1814?
CVE-2025-1814 is classified as a critical vulnerability.
2
What functionality is affected by CVE-2025-1814?
CVE-2025-1814 affects the unknown functionality of the file /goform/WifiExtraSet in Tenda AC6.
3
What type of vulnerability is CVE-2025-1814?
CVE-2025-1814 is a stack-based buffer overflow vulnerability.
4
How can CVE-2025-1814 be exploited?
CVE-2025-1814 can be exploited by manipulating the argument wpapsk_crypto.
5
Which devices are affected by CVE-2025-1814?
CVE-2025-1814 affects the Tenda AC6 running firmware version 15.03.05.16.