CVE-2025-8940: Tenda AC20 saveParentControlInfo strcpy buffer overflow
A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this vulnerability is the function strcpy of the file /goform/saveParentControlInfo. The manipulation of the argument Time leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8940?
CVE-2025-8940 is considered a high severity vulnerability due to its potential for remote exploitation leading to buffer overflow.
How do I fix CVE-2025-8940?
To fix CVE-2025-8940, update your Tenda AC20 device to a version higher than 16.03.08.12.
What are the potential impacts of CVE-2025-8940?
The potential impacts of CVE-2025-8940 include remote code execution and system compromise due to buffer overflow.
Who is affected by CVE-2025-8940?
CVE-2025-8940 affects Tenda AC20 devices running version 16.03.08.12 or earlier.
How does CVE-2025-8940 work?
CVE-2025-8940 works by manipulating the time argument in the strcpy function, leading to a buffer overflow vulnerability.