CVE-2025-7419: Tenda O3V2 httpd setRateTest fromSpeedTestSet stack-based overflow
Published Jul 10, 2025
·Updated
A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been classified as critical. This affects the function fromSpeedTestSet of the file /goform/setRateTest of the component httpd. The manipulation of the argument destIP leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda O3V2
All of the following
Tenda O3 Firmware=1.0.0.12\(3880\)
Tenda O3=2.0
Event History
Jul 10, 2025
CVE Published
via MITRE·11:02 PM
Data Sourced
via MITRE·11:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 7, 57553
Event
via FIRST·06:57 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-7419?
CVE-2025-7419 has been classified as critical.
2
What component is affected by CVE-2025-7419?
CVE-2025-7419 affects the httpd component in Tenda O3V2.
3
What kind of vulnerability is CVE-2025-7419?
CVE-2025-7419 is a stack-based buffer overflow vulnerability.
4
How do I fix CVE-2025-7419?
To fix CVE-2025-7419, update the Tenda O3V2 firmware to the latest version.
5
What function is related to CVE-2025-7419?
The vulnerability in CVE-2025-7419 is related to the fromSpeedTestSet function in the setRateTest file.