CVE-2025-9023: Tenda AC7/AC18 SetLEDCfg formSetSchedLed buffer overflow
A vulnerability has been found in Tenda AC7 and AC18 15.03.05.19/15.03.06.44. Affected is the function formSetSchedLed of the file /goform/SetLEDCfg. The manipulation of the argument Time leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9023?
CVE-2025-9023 is classified as a high-severity vulnerability due to its potential for remote exploitation and the risk of buffer overflow.
How do I fix CVE-2025-9023?
To fix CVE-2025-9023, users should update their Tenda AC7 and AC18 devices to the latest firmware version provided by the vendor.
What systems are affected by CVE-2025-9023?
CVE-2025-9023 affects Tenda AC7 and AC18 devices running firmware versions 15.03.05.19 and 15.03.06.44 respectively.
What type of attack can exploit CVE-2025-9023?
CVE-2025-9023 can be exploited through a remote attack that manipulates the function formSetSchedLed to induce a buffer overflow.
Is CVE-2025-9023 easy to exploit?
Yes, CVE-2025-9023 is considered easy to exploit, allowing attackers to execute arbitrary code remotely.