CVE-2025-1853Improper Restriction of Operations within the Bounds of a Memory Buffer in AC8

Severity
8.7HIGHNVD
EPSS
0.8%
top 25.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 3
Latest updateOct 10

Description

A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical. This issue affects the function sub_49E098 of the file /goform/SetIpMacBind of the component Parameter Handler. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5tenda/ac816.03.34.06
NVDtenda/ac8_firmware16.03.34.06

🔴Vulnerability Details

2
CVEList
Tenda AC8 Parameter SetIpMacBind sub_49E098 stack-based overflow2025-03-03
GHSA
GHSA-vmg3-6qh8-v3m9: A vulnerability was found in Tenda AC8 162025-03-03

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS Tenda SetIpMacBind Multiple Parameters Buffer Overflow Attempt (CVE-2025-15216, CVE-2025-9089, CVE-2025-1853, CVE-2024-40417, CVE-2023-41556, CVE-2023-40902, CVE-2023-40896)2025-10-10
CVE-2025-1853 — Tenda AC8 vulnerability | cvebase