CVE-2025-3328
published 2025-04-07CVE-2025-3328: A vulnerability was found in Tenda AC1206 15.03.06.23. It has been classified as critical. Affected is the function form_fast_setting_wifi_set of the file…
PriorityP269high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
6.44%
92.9th percentile
A vulnerability was found in Tenda AC1206 15.03.06.23. It has been classified as critical. Affected is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid/timeZone leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | ac1206 | — | — |
| tenda | ac1206_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Tenda AC1206 fast_setting_wifi_set timeZone or ssid parameter Buffer Overflow Attempt (CVE-2025-3328, CVE-2025-51082))"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:29; content:"/goform/fast_setting_wifi_set"; fast_pattern; http.request_body; pcre:"/^.*?(?:ssid|timeZone)\x3d[^&]{100,}(?:&|$)/R"; reference:cve,2025-3328; reference:url,github.com/CH13hh/tmp_store_cc/blob/main/AC1206/AC1206form_fast_setting_wifi_set_time/time.md; reference:url,github.com/CH13hh/tmp_store_cc/blob/main/AC1206/AC1206form_fast_setting_wifi_set/form_fast_setting_wifi_set.md; reference:cve,2025-51082; reference:url,github.com/TL-SN/IOT; classtype:web-application-attack; sid:2061417; rev:2; metadata:affected_product Tenda, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_04_09, cve CVE_2025_3328, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, updated_at 2025_07_25, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)- →Match HTTP POST requests to the exact URI /goform/fast_setting_wifi_set with a URI byte size of exactly 29 bytes.
- →Detect buffer overflow attempts by inspecting the POST body for ssid or timeZone parameters with values of 100 or more characters (indicative of overflow payload).
- →The attack is plaintext only (tls_state plaintext); TLS-encrypted traffic to the device would not carry this exploit.
- →The vulnerability is exploitable remotely without authentication; perimeter and internal deployment of the detection rule is recommended.
- →Public exploit proof-of-concept code is available and may be actively used; treat detections as high-confidence exploitation attempts.
- →Other POST body parameters beyond ssid and timeZone in the same endpoint may also be vulnerable and worth monitoring.
- ·The Snort/Suricata rule (sid:2061417, rev:2) covers both CVE-2025-3328 and CVE-2025-51082 in a single signature; analysts should be aware that a single alert may correspond to either CVE.
- ·The affected firmware version is 15.03.06.23; detections should be scoped to Tenda AC1206 devices running this version. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Tenda AC1206 fast_setting_wifi_set timeZone or ssid parameter Buffer Overflow Attempt (CVE-2025-3328, CVE-2025-51082))
suricata·2025-04-09·CVSS 8.7
CVE-2025-3328 [HIGH] ET WEB_SPECIFIC_APPS Tenda AC1206 fast_setting_wifi_set timeZone or ssid parameter Buffer Overflow Attempt (CVE-2025-3328, CVE-2025-51082))
ET WEB_SPECIFIC_APPS Tenda AC1206 fast_setting_wifi_set timeZone or ssid parameter Buffer Overflow Attempt (CVE-2025-3328, CVE-2025-51082))
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Tenda AC1206 fast_setting_wifi_set timeZone or ssid parameter Buffer Overflow Attempt (CVE-2025-3328, CVE-2025-51082))"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:29; content:"/goform/fast_setting_wifi_set"; fast_pattern; http.request_body; pcre:"/^.*?(?:ssid|timeZone)\x3d[^&]{100,}(?:&|$)/R"; reference:cve,2025-3328; reference:url,github.com/CH13hh/tmp_store_cc/blob/main/AC1206/AC1206form_fast_setting_wifi_set_time/time.md; reference:url,github.com/CH13hh/tmp_store_cc/blob/main/AC1206/AC1206form_fast_setting_wifi_set/form_fast_setting_wifi_set.md; refe
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/CH13hh/tmp_store_cc/blob/main/AC1206/AC1206form_fast_setting_wifi_set/form_fast_setting_wifi_set.mdhttps://github.com/CH13hh/tmp_store_cc/blob/main/AC1206/AC1206form_fast_setting_wifi_set_time/time.mdhttps://vuldb.com/?ctiid.303540https://vuldb.com/?id.303540https://vuldb.com/?submit.551893https://www.tenda.com.cn/https://github.com/CH13hh/tmp_store_cc/blob/main/AC1206/AC1206form_fast_setting_wifi_set/form_fast_setting_wifi_set.mdhttps://github.com/CH13hh/tmp_store_cc/blob/main/AC1206/AC1206form_fast_setting_wifi_set_time/time.md
2025-04-07
Published