CVE-2025-7420: Tenda O3V2 httpd setWrlBasicInfo formWifiBasicSet stack-based overflow
A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been declared as critical. This vulnerability affects the function formWifiBasicSet of the file /goform/setWrlBasicInfo of the component httpd. The manipulation of the argument extChannel leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7420?
CVE-2025-7420 has been declared as critical.
What components are affected by CVE-2025-7420?
CVE-2025-7420 affects the httpd component specifically within the function formWifiBasicSet.
What kind of attack does CVE-2025-7420 enable?
CVE-2025-7420 enables stack-based buffer overflow attacks via manipulation of the extChannel argument.
How do I fix CVE-2025-7420?
To fix CVE-2025-7420, ensure you apply the latest firmware update provided by Tenda for the O3V2.
Which product is impacted by CVE-2025-7420?
CVE-2025-7420 impacts the Tenda O3V2 device running version 1.0.0.12(3880).