CVE-2025-7416: Tenda O3V2 httpd setSysTimeInfo fromSysToolTime stack-based overflow
Published Jul 10, 2025
·Updated
A vulnerability, which was classified as critical, was found in Tenda O3V2 1.0.0.12(3880). Affected is the function fromSysToolTime of the file /goform/setSysTimeInfo of the component httpd. The manipulation of the argument Time leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda O3V2
All of the following
Tenda O3 Firmware=1.0.0.12\(3880\)
Tenda O3=2.0
Event History
Jul 10, 2025
CVE Published
via MITRE·09:32 PM
Data Sourced
via MITRE·09:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 13, 58473
Event
via NVD·03:38 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-7416?
CVE-2025-7416 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-7416?
CVE-2025-7416 is a stack-based buffer overflow vulnerability.
3
How do I fix CVE-2025-7416?
To fix CVE-2025-7416, update the Tenda O3V2 to the latest firmware version provided by the vendor.
4
What component is affected by CVE-2025-7416?
CVE-2025-7416 affects the httpd component in Tenda O3V2.
5
What function in the Tenda O3V2 is involved in CVE-2025-7416?
The function involved in CVE-2025-7416 is fromSysToolTime located in the file /goform/setSysTimeInfo.