CVE-2025-5851: Tenda AC15 HTTP POST Request AdvSetLanip fromadvsetlanip buffer overflow
A vulnerability was found in Tenda AC15 15.03.05.19multi. It has been rated as critical. This issue affects the function fromadvsetlanip of the file /goform/AdvSetLanip of the component HTTP POST Request Handler. The manipulation of the argument lanMask leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5851?
CVE-2025-5851 has been rated as critical due to the potential for a buffer overflow.
How does CVE-2025-5851 affect the Tenda AC15 firmware?
CVE-2025-5851 affects the function fromadvsetlanip in the /goform/AdvSetLanip file, leading to possible buffer overflow vulnerabilities.
What causes the vulnerability in CVE-2025-5851?
The vulnerability in CVE-2025-5851 is caused by the manipulation of the argument lanMask.
How can I protect my device from CVE-2025-5851?
To protect your device from CVE-2025-5851, ensure the firmware is updated to a version that addresses this vulnerability.
Is my Tenda AC15 device affected by CVE-2025-5851?
Yes, the Tenda AC15 running firmware version 15.03.05.19_multi is affected by CVE-2025-5851.