CVE-2025-8017: Tenda AC7 httpd setMacFilterCfg formSetMacFilterCfg stack-based overflow
A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function formSetMacFilterCfg of the file /goform/setMacFilterCfg of the component httpd. The manipulation of the argument deviceList leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8017?
CVE-2025-8017 is classified as critical due to its stack-based buffer overflow vulnerability.
How do I fix CVE-2025-8017?
To fix CVE-2025-8017, update your Tenda AC7 firmware to the latest version released by the vendor.
What components are affected by CVE-2025-8017?
CVE-2025-8017 affects the httpd component specifically through the formSetMacFilterCfg function.
What specific vulnerability occurs in CVE-2025-8017?
CVE-2025-8017 involves a stack-based buffer overflow triggered by manipulation of the deviceList argument.
Which device is impacted by CVE-2025-8017?
CVE-2025-8017 impacts the Tenda AC7 router.