CVE-2025-3786Improper Restriction of Operations within the Bounds of a Memory Buffer in Ac15

Severity
8.7HIGHNVD
EPSS
0.6%
top 29.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 18

Description

A vulnerability was found in Tenda AC15 up to 15.03.05.19 and classified as critical. This issue affects the function fromSetWirelessRepeat of the file /goform/WifiExtraSet. The manipulation of the argument mac leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5tenda/ac1520 versions+19
NVDtenda/ac15_firmware15.03.05.19

🔴Vulnerability Details

2
GHSA
GHSA-68p2-2v8j-wr5h: A vulnerability was found in Tenda AC15 up to 152025-04-18
CVEList
Tenda AC15 WifiExtraSet fromSetWirelessRepeat buffer overflow2025-04-18
CVE-2025-3786 — Tenda Ac15 vulnerability | cvebase