CVE-2025-3786

A vulnerability was found in Tenda AC15 up to 15.03.05.19 and classified as critical. This issue affects the function fromSetWirelessRepeat of the file /goform/WifiExtraSet. The manipulation of the argument mac leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/CH13hh/cve/tree/AC15WifiExtraSet Exploit Third Party Advisory
https://github.com/CH13hh/cve/tree/AC15WifiExtraSet Exploit Third Party Advisory
https://vuldb.com/?ctiid.305609 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.305609 Third Party Advisory VDB Entry
https://vuldb.com/?submit.553703 Third Party Advisory VDB Entry
https://www.tenda.com.cn/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac15_firmware:15.03.05.19:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac15:-:*:*:*:*:*:*:*

History

22 Apr 2025, 16:35

Type Values Removed Values Added
CWE CWE-120
First Time Tenda ac15 Firmware
Tenda
Tenda ac15
CPE cpe:2.3:h:tenda:ac15:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac15_firmware:15.03.05.19:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product
References () https://vuldb.com/?ctiid.305609 - () https://vuldb.com/?ctiid.305609 - Permissions Required, Third Party Advisory, VDB Entry
References () https://vuldb.com/?id.305609 - () https://vuldb.com/?id.305609 - Third Party Advisory, VDB Entry
References () https://github.com/CH13hh/cve/tree/AC15WifiExtraSet - () https://github.com/CH13hh/cve/tree/AC15WifiExtraSet - Exploit, Third Party Advisory
References () https://vuldb.com/?submit.553703 - () https://vuldb.com/?submit.553703 - Third Party Advisory, VDB Entry

18 Apr 2025, 12:15

Type Values Removed Values Added
CWE CWE-120
CWE-119
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : unknown

18 Apr 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-18 09:15

Updated : 2025-04-22 16:35


NVD link : CVE-2025-3786

Mitre link : CVE-2025-3786


JSON object : View

Products Affected

tenda

  • ac15
  • ac15_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')