CVE-2025-29384: Critical severity Tenda Ac9 vulnerability
In Tenda AC9 v1.0 V15.03.05.14multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29384?
CVE-2025-29384 is classified as a critical vulnerability due to its potential for remote arbitrary code execution.
How do I fix CVE-2025-29384?
To mitigate CVE-2025-29384, it is recommended to update the Tenda AC9 router firmware to the latest version provided by the manufacturer.
What kind of vulnerability is CVE-2025-29384?
CVE-2025-29384 is a stack overflow vulnerability specifically affecting the wanMTU parameter in Tenda AC9 routers.
Who is affected by CVE-2025-29384?
Users of the Tenda AC9 router and other associated models running v15.03.05.14_multi are affected by CVE-2025-29384.
What could happen if CVE-2025-29384 is exploited?
Exploitation of CVE-2025-29384 could lead to remote arbitrary code execution, allowing attackers to take full control of the affected device.