CVE-2025-5609: Tenda AC18 AdvSetLanip fromadvsetlanip buffer overflow
Published Jun 4, 2025
·Updated
A vulnerability classified as critical was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda Ac18
All of the following
Tenda Ac18 Firmware=15.03.05.05
Tenda Ac18
Event History
Jun 4, 2025
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 30, 57482
Event
via FIRST·06:20 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-5609?
CVE-2025-5609 is classified as a critical vulnerability.
2
How do I fix CVE-2025-5609?
To fix CVE-2025-5609, update the firmware of the Tenda AC18 to the latest version.
3
What type of attack can be executed via CVE-2025-5609?
CVE-2025-5609 can be exploited through a remote buffer overflow attack.
4
Which function is affected by CVE-2025-5609?
CVE-2025-5609 affects the function fromadvsetlanip in the file /goform/AdvSetLanip.
5
What is the potential impact of exploiting CVE-2025-5609?
Exploiting CVE-2025-5609 can lead to unauthorized access and control over the affected device.