Junglewise Threat Intelligence

CVE-2025-51087: Tenda AC8V4 stack overflow in saveParentControlInfo

CVE-2025-51087 · Severity: high · CVSS 8.6 · Published 2025-07-24

Technologies: Tenda Ac8, Tenda Ac8 Firmware, Tenda AC8V4. Vendors: Tenda.

Executive brief

A vulnerability exists in the Tenda AC8V4 router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw by sending a specially crafted web request to the router's management interface. This could lead to a device crash, causing a service outage, or potentially allow the attacker to gain unauthorized control over the router and the data passing through it.

Technical details

A stack-based buffer overflow (CWE-121) exists in the Tenda AC8V4 router firmware version V16.03.34.06. The vulnerability is located within the 'compare_parentcontrol_time' function, which processes requests sent to the '/goform/saveParentControlInfo' endpoint. The root cause is the use of the 'sscanf' function to copy the user-supplied 'time' POST parameter into a fixed-size stack buffer without adequate length validation. A remote, unauthenticated attacker can exploit this by sending a long string in the 'time' argument, leading to memory corruption. This can result in a denial-of-service (DoS) condition or potentially arbitrary code execution.

Affected products

  • Tenda AC8V4 V16.03.34.06

Timeline

  • 2025-07-24: disclosed
  • 2025-07-24: advisory

References

Related threats