CVE-2025-4368: Tenda AC8 MtuSetMacWan formGetRouterStatus buffer overflow
Published May 6, 2025
·Updated
A vulnerability, which was classified as critical, was found in Tenda AC8 16.03.34.06. Affected is the function formGetRouterStatus of the file /goform/MtuSetMacWan. The manipulation of the argument shareSpeed leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda AC8=16.03.34.06
All of the following
Tenda Ac8 Firmware=16.03.34.06
Tenda AC8
Event History
May 6, 2025
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-4368?
CVE-2025-4368 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-4368?
CVE-2025-4368 is a buffer overflow vulnerability found in Tenda AC8 firmware.
3
How do I fix CVE-2025-4368?
To fix CVE-2025-4368, upgrade your Tenda AC8 firmware to the latest version provided by the vendor.
4
What can an attacker do with CVE-2025-4368?
An attacker can exploit CVE-2025-4368 to perform a remote attack due to the buffer overflow.
5
Which versions of Tenda AC8 are affected by CVE-2025-4368?
CVE-2025-4368 affects Tenda AC8 version 16.03.34.06 specifically.