CVE-2025-5794: Tenda AC5 setPptpUserList formSetPPTPUserList buffer overflow
Published Jun 6, 2025
·Updated
A vulnerability, which was classified as critical, has been found in Tenda AC5 15.03.06.47. Affected by this issue is the function formSetPPTPUserList of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda AC5
All of the following
Tenda Ac5 Firmware=15.03.06.47
Tenda AC5=1.0
Event History
Jun 6, 2025
CVE Published
via MITRE·06:31 PM
Data Sourced
via MITRE·06:31 PM
DescriptionSeverityWeakness
Feb 20, 57488
Event
via FIRST·02:08 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-5794?
CVE-2025-5794 is classified as a critical vulnerability.
2
How do I fix CVE-2025-5794?
To mitigate CVE-2025-5794, users should update their Tenda AC5 firmware to the latest version.
3
What type of vulnerability is CVE-2025-5794?
CVE-2025-5794 is a buffer overflow vulnerability.
4
What is affected by CVE-2025-5794?
CVE-2025-5794 affects the Tenda AC5 router, specifically the function formSetPPTPUserList.
5
Can CVE-2025-5794 be exploited remotely?
Yes, the CVE-2025-5794 vulnerability can be exploited remotely.