CVE-2025-9087: Tenda AC20 SetNetControlList Endpoint set_qosMib_list stack-based overflow
A vulnerability has been found in Tenda AC20 16.03.08.12. This affects the function setqosMiblist of the file /goform/SetNetControlList of the component SetNetControlList Endpoint. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9087?
CVE-2025-9087 has a high severity rating due to the potential for a stack-based buffer overflow.
How do I fix CVE-2025-9087?
To fix CVE-2025-9087, update the Tenda AC20 firmware to the latest version provided by the manufacturer.
What systems are affected by CVE-2025-9087?
CVE-2025-9087 affects the Tenda AC20 router running firmware version 16.03.08.12.
What is the impact of exploiting CVE-2025-9087?
Exploiting CVE-2025-9087 can allow an attacker to execute arbitrary code on the affected device.
How can I mitigate the risks of CVE-2025-9087?
Mitigation strategies for CVE-2025-9087 include disabling remote management and applying the necessary firmware updates.