CVE-2025-29137: Buffer Overflow
Published Mar 19, 2025
·Updated
Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the formfastsettingwifiset function, which can cause RCE.
Affected Software
3 affected components
Tenda AC7
All of the following
Tenda AC7 firmware=15.03.06.44
Tenda AC7=1.0
Event History
Mar 19, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29137?
CVE-2025-29137 has a critical severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2025-29137?
To fix CVE-2025-29137, update the Tenda AC7 firmware to the latest version provided by the vendor.
3
What systems are affected by CVE-2025-29137?
CVE-2025-29137 affects Tenda AC7 routers, including versions AC9 and AC10.
4
What is the nature of the vulnerability in CVE-2025-29137?
CVE-2025-29137 is a buffer overflow vulnerability linked to the timeZone parameter in the form_fast_setting_wifi_set function.
5
Can CVE-2025-29137 lead to a security breach?
Yes, CVE-2025-29137 can lead to a security breach due to its capability for remote code execution.