CVE-2025-8939: Tenda AC20 WifiGuestSet buffer overflow
A vulnerability was determined in Tenda AC20 up to 16.03.08.12. Affected is an unknown function of the file /goform/WifiGuestSet. The manipulation of the argument shareSpeed leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8939?
CVE-2025-8939 is classified as a high-severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2025-8939?
To fix CVE-2025-8939, update your Tenda AC20 router firmware to version 16.03.08.12 or later.
What does CVE-2025-8939 exploit?
CVE-2025-8939 exploits a buffer overflow in the /goform/WifiGuestSet function in the Tenda AC20 firmware.
Is CVE-2025-8939 easily exploitable?
Yes, CVE-2025-8939 can be exploited remotely, making it critical for users to apply updates immediately.
What are the implications of CVE-2025-8939?
Exploitation of CVE-2025-8939 could allow attackers to execute arbitrary code on affected Tenda AC20 devices.