← Back to CVE List
Vulnerability Intelligence Report

CVE-2025-29462

A buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile function calls the socketRead function to process HTTP request messages, resulting in the overwriting of a buffer on the stack.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.49%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-120 ↗CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Affected Products & Versions

Vendor Product Affected Versions
tenda ac15_firmware 15.13.07.13
tenda ac15 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.494%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2025-03-11T00:00:00
Published2025-04-03T00:00:00
Last Updated2025-04-07T14:54:47

LINK COPIED TO CLIPBOARD