CVE-2025-5862: Tenda AC7 setPptpUserList formSetPPTPUserList buffer overflow
Published Jun 9, 2025
·Updated
A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. This issue affects the function formSetPPTPUserList of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
All of the following
Tenda AC7 firmware=15.03.06.44
Tenda AC7=1.0
Event History
Jun 9, 2025
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionSeverityWeakness
May 8, 57496
Event
via FIRST·09:49 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-5862?
CVE-2025-5862 is classified as a critical vulnerability.
2
How does CVE-2025-5862 impact Tenda AC7 devices?
CVE-2025-5862 affects Tenda AC7 devices by allowing remote attackers to exploit a buffer overflow in the formSetPPTPUserList function.
3
Can CVE-2025-5862 be exploited remotely?
Yes, CVE-2025-5862 can be exploited remotely.
4
What versions are affected by CVE-2025-5862?
CVE-2025-5862 affects Tenda AC7 devices running firmware version 15.03.06.44.
5
How can users mitigate CVE-2025-5862?
To mitigate CVE-2025-5862, users should upgrade their firmware to the latest version released by Tenda.