CVE-2025-22946: Critical severity tenda ac7/ac9/ac10 routers vulnerability
Published Jan 10, 2025
·Updated
Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.
Affected Software
1 affected component
Tenda Ac9
Event History
Jan 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-22946?
CVE-2025-22946 is considered a high severity vulnerability due to its potential for remote arbitrary code execution.
2
How do I fix CVE-2025-22946?
To fix CVE-2025-22946, you should update the Tenda AC9 to the latest firmware version that addresses this vulnerability.
3
What causes CVE-2025-22946?
CVE-2025-22946 is caused by a stack overflow vulnerability in the /goform/SetOnlineDevName function of the Tenda AC9 firmware.
4
What are the potential impacts of exploiting CVE-2025-22946?
Exploitation of CVE-2025-22946 may lead to remote arbitrary code execution, allowing an attacker to execute malicious code on the affected device.
5
Which devices are affected by CVE-2025-22946?
CVE-2025-22946 specifically affects the Tenda AC9 V1.0 firmware version 15.03.05.19.