CVE-2025-8940

A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this vulnerability is the function strcpy of the file /goform/saveParentControlInfo. The manipulation of the argument Time leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac20:-:*:*:*:*:*:*:*

History

19 Aug 2025, 18:42

Type Values Removed Values Added
First Time Tenda ac20 Firmware
Tenda ac20
Tenda
CPE cpe:2.3:o:tenda:ac20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac20:-:*:*:*:*:*:*:*
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product
References () https://vuldb.com/?submit.631836 - () https://vuldb.com/?submit.631836 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?ctiid.319903 - () https://vuldb.com/?ctiid.319903 - Permissions Required, VDB Entry
References () https://github.com/lin-3-start/lin-cve/blob/main/Tenda%20AC20-2/Tenda%20AC20-2.md - () https://github.com/lin-3-start/lin-cve/blob/main/Tenda%20AC20-2/Tenda%20AC20-2.md - Exploit, Third Party Advisory
References () https://github.com/lin-3-start/lin-cve/blob/main/Tenda%20AC20-2/Tenda%20AC20-2.md#poc - () https://github.com/lin-3-start/lin-cve/blob/main/Tenda%20AC20-2/Tenda%20AC20-2.md#poc - Exploit, Third Party Advisory
References () https://vuldb.com/?id.319903 - () https://vuldb.com/?id.319903 - Third Party Advisory, VDB Entry

15 Aug 2025, 13:15

Type Values Removed Values Added
CWE CWE-120
CWE-119
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : unknown

14 Aug 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-14 06:15

Updated : 2025-08-19 18:42


NVD link : CVE-2025-8940

Mitre link : CVE-2025-8940


JSON object : View

Products Affected

tenda

  • ac20_firmware
  • ac20
CWE

No CWE.