CVE-2025-9088: Tenda AC20 formSetVirtualSer save_virtualser_data stack-based overflow
A vulnerability was found in Tenda AC20 16.03.08.12. This vulnerability affects the function savevirtualserdata of the file /goform/formSetVirtualSer. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9088?
CVE-2025-9088 has been classified as a high-severity vulnerability due to the potential for remote exploitation leading to stack-based buffer overflow.
How does CVE-2025-9088 affect Tenda AC20 devices?
CVE-2025-9088 affects the Tenda AC20 by enabling remote attackers to manipulate the 'save_virtualser_data' function, potentially leading to arbitrary code execution.
How do I fix CVE-2025-9088?
To fix CVE-2025-9088, users should apply the latest firmware updates provided by Tenda that address this specific vulnerability.
Can CVE-2025-9088 be exploited remotely?
Yes, CVE-2025-9088 can be exploited remotely, allowing attackers to execute arbitrary code without physical access to the device.
What are the potential consequences of CVE-2025-9088 exploitation?
Exploitation of CVE-2025-9088 can lead to unauthorized access, data loss, or disruption of services on the affected Tenda AC20 devices.