Junglewise Threat Intelligence

CVE-2025-51082: Tenda AC8V4 stack overflow in fast_setting_wifi_set

CVE-2025-51082 · Severity: medium · CVSS 5.3 · Published 2025-07-24

Technologies: Tenda Ac8, Tenda Ac8 Firmware, Tenda AC8V4. Vendors: Tenda.

Executive brief

A vulnerability exists in the Tenda AC8V4 wireless router, a device used to provide home and small office internet connectivity. An attacker can send a specially crafted web request to the router's configuration interface to cause the device to crash or become unresponsive. This could lead to a loss of internet connectivity for all connected users and may require a manual restart of the hardware to restore service.

Technical details

A stack-based buffer overflow (CWE-121) exists in the Tenda AC8V4 router firmware version V16.03.34.06. The vulnerability is located within the 'form_fast_setting_wifi_set' function at the '/goform/fast_setting_wifi_set' endpoint. The application retrieves the 'timeZone' parameter from a POST request and processes it using the 'strcpy' function without performing adequate length validation. By providing a sufficiently long string in the 'timeZone' field, an unauthenticated remote attacker can overwrite the stack, leading to a denial-of-service (DoS) condition. Successful exploitation requires bypassing a check on the 'ssid' parameter to reach the vulnerable code path at address 0x044DB3C.

Affected products

  • Tenda AC8V4 V16.03.34.06

Timeline

  • 2025-07-24: disclosed: Initial disclosure and NVD publication

References

Related threats