CVE-2025-3346: Tenda AC7 SetPptpServerCfg formSetPPTPServer buffer overflow
A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. Affected by this issue is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument pptpserverstartip/pptpserverendip leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3346?
CVE-2025-3346 is rated as critical due to its potential to cause a buffer overflow.
How do I fix CVE-2025-3346?
To fix CVE-2025-3346, it is recommended to update the firmware of the Tenda AC7 router to the latest version provided by Tenda.
What are the affected devices for CVE-2025-3346?
CVE-2025-3346 affects Tenda AC7 routers running version 15.03.06.44.
What is the impact of CVE-2025-3346?
The impact of CVE-2025-3346 includes potential remote code execution due to a buffer overflow vulnerability.
How can I protect my network from CVE-2025-3346?
To protect your network from CVE-2025-3346, ensure your Tenda AC7 router firmware is updated and disable unnecessary services.