CVE-2025-71020: High severity Tenda AX-1806 vulnerability
Published Jan 16, 2026
·Updated
Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub4C408 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Affected Software
3 affected components
Tenda AX-1806
All of the following
Tenda Ax1806 Firmware=1.0.0.1
Tenda AX1806
Event History
Jan 16, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-71020?
CVE-2025-71020 is classified as a high severity vulnerability due to its potential to cause Denial of Service.
2
How do I fix CVE-2025-71020?
The recommended fix for CVE-2025-71020 is to update the Tenda AX-1806 firmware to the latest version released by the manufacturer.
3
What type of attack does CVE-2025-71020 allow?
CVE-2025-71020 allows attackers to perform a Denial of Service (DoS) attack through a crafted request.
4
Which device is affected by CVE-2025-71020?
The Tenda AX-1806 device is affected by CVE-2025-71020.
5
Is CVE-2025-71020 remotely exploitable?
Yes, CVE-2025-71020 can be exploited remotely by sending a specially crafted request to the vulnerable device.