Junglewise Threat Intelligence

CVE-2025-61498: Tenda AC8 buffer overflow in UPnP service

CVE-2025-61498 · Severity: high · CVSS 7.5 · Published 2025-10-30

Technologies: Tenda Ac8, Tenda Ac8 Firmware. Vendors: Tenda.

Executive brief

A security vulnerability has been identified in the Tenda AC8 router, a device used to provide wireless internet connectivity. An attacker can send a specially crafted network packet to the device's UPnP service to cause it to crash or become unresponsive. This results in a denial-of-service, disrupting internet access for all connected users and requiring a manual restart of the hardware.

Technical details

A stack-based buffer overflow (CWE-121) exists in the UPnP service of Tenda AC8 hardware running firmware version v03.03.10.01. The vulnerability is triggered when the service processes a specially crafted network packet, leading to memory corruption. This is a network-reachable exploit that requires no authentication or user interaction. Successful exploitation results in a Denial of Service (DoS) condition, crashing the service or the entire device. No official patch or mitigation was detailed in the advisory, though disabling UPnP is a standard workaround for such vulnerabilities.

Affected products

  • Tenda AC8 v03.03.10.01

Timeline

  • 2025-10-30: disclosed
  • 2025-10-30: advisory

References

Related threats