CVE-2025-29215: Medium severity Tenda AX12 vulnerability
Published Mar 20, 2025
·Updated
Tenda AX12 v22.03.01.46CN was discovered to contain a stack overflow via the sub43fdcc function at /goform/SetNetControlList.
Affected Software
3 affected components
Tenda AX12
All of the following
Tenda Ax12 Firmware=22.03.01.46_cn
Tenda AX12
Event History
Mar 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Aug 3, 57203
Event
via FIRST·06:05 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-29215?
CVE-2025-29215 is classified as a critical vulnerability due to its potential to allow remote code execution via a stack overflow.
2
How do I fix CVE-2025-29215?
To fix CVE-2025-29215, you should update the Tenda AX12 to the latest firmware version provided by the vendor.
3
What systems are affected by CVE-2025-29215?
CVE-2025-29215 affects the Tenda AX12 router running firmware version v22.03.01.46_CN or earlier.
4
What type of vulnerability is CVE-2025-29215?
CVE-2025-29215 is a stack overflow vulnerability that can be exploited through the sub_43fdcc function in the affected firmware.
5
Can CVE-2025-29215 be exploited remotely?
Yes, CVE-2025-29215 can be exploited remotely, allowing attackers to execute arbitrary code if they send specially crafted input to the vulnerable device.