Executive brief
A security vulnerability exists in the Tenda AC15 router, a device used to provide wireless internet connectivity. An attacker can send a specially crafted request to the router's management interface to cause the device to crash or become unresponsive. This could lead to a total loss of internet connectivity for all connected users and require a manual restart of the hardware.
Technical details
A stack-based buffer overflow (CWE-121) exists in Tenda AC15 firmware version 15.03.05.19_multi_TD01. The vulnerability is located within the 'fromSetIpMacBind' function, which fails to properly validate the length of the 'list' parameter provided in a POST request to '/goform/SetIpMacBind'. An unauthenticated remote attacker can exploit this by sending an oversized payload in the 'list' parameter, leading to memory corruption. While the reported impact is primarily service unavailability (DoS), stack overflows of this nature can potentially be leveraged for remote code execution (RCE). No official patch is currently noted in the advisory.
Affected products
- Tenda AC15 firmware 15.03.05.19_multi_TD01
Timeline
- 2025-08-21: advisory
- 2025-08-21: disclosed