CVE-2025-7796: Tenda FH451 PPTPDClient fromPptpUserAdd stack-based overflow
A vulnerability, which was classified as critical, was found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserAdd of the file /goform/PPTPDClient. The manipulation of the argument Username leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7796?
CVE-2025-7796 is classified as a critical vulnerability.
How do I fix CVE-2025-7796?
To mitigate CVE-2025-7796, update the Tenda FH451 to the latest firmware version provided by the vendor.
What underlying issue does CVE-2025-7796 exploit?
CVE-2025-7796 exploits a stack-based buffer overflow vulnerability in the fromPptpUserAdd function.
Who is affected by CVE-2025-7796?
CVE-2025-7796 affects users of the Tenda FH451 router running version 1.0.0.9.
Can CVE-2025-7796 be exploited remotely?
Yes, CVE-2025-7796 can be exploited remotely if the vulnerable function is accessible.