CVE-2025-5847: Tenda AC9 HTTP POST Request SetRemoteWebCfg formSetSafeWanWebMan stack-based overflow
A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation of the argument remoteIp leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5847?
CVE-2025-5847 is classified as critical due to its potential impact on the security of the affected device.
How do I fix CVE-2025-5847?
To fix CVE-2025-5847, update your Tenda AC9 firmware to a version that addresses this vulnerability.
What is affected by CVE-2025-5847?
CVE-2025-5847 affects the Tenda AC9 firmware version 15.03.02.13.
What type of attack does CVE-2025-5847 allow?
CVE-2025-5847 allows for unauthorized remote access to the device, compromising its security.
Is my Tenda AC9 router vulnerable to CVE-2025-5847?
Yes, if you are running firmware version 15.03.02.13 on your Tenda AC9 router, you are vulnerable to CVE-2025-5847.