CVE-2025-9605: Tenda AC21/AC23 GetParentControlInfo stack-based overflow
A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. Such manipulation of the argument mac leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9605?
CVE-2025-9605 is categorized as a high severity vulnerability due to the potential for remote exploitation.
How do I fix CVE-2025-9605?
To fix CVE-2025-9605, update the firmware of the Tenda AC21 and AC23 routers to the latest version provided by the vendor.
What types of devices are affected by CVE-2025-9605?
CVE-2025-9605 affects the Tenda AC21 and AC23 router models.
What kind of attack can be launched due to CVE-2025-9605?
An attacker can execute a remote stack-based buffer overflow attack via manipulated arguments.
Is user authentication required to exploit CVE-2025-9605?
CVE-2025-9605 can be exploited remotely without the need for user authentication.