CVE-2025-14992

Published Dec 21, 2025

Last updated 2 months ago

Overview

Description
A security vulnerability has been detected in Tenda AC18 15.03.05.05. The impacted element is the function strcpy of the file /goform/GetParentControlInfo of the component HTTP Request Handler. The manipulation of the argument mac leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Source
cna@vuldb.com
NVD status
Analyzed
Products
ac18_firmware

Risk scores

CVSS 4.0

Type
Secondary
Base score
7.4
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

CVSS 2.0

Type
Secondary
Base score
9
Impact score
10
Exploitability score
8
Vector string
AV:N/AC:L/Au:S/C:C/I:C/A:C

Weaknesses

cna@vuldb.com
CWE-119

Social media

Hype score
Not currently trending
  1. CVE-2025-14992 (CVSS:7.4, HIGH) is Undergoing Analysis. A security vulnerability has been detected in Tenda AC18 15.03.05.05. The impacted element is the function strcpy of the..https://t.co/69h91Fb5vG #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    26 Dec 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. A lot of offensive activities were identified targeting Tenda AC18 (CVE-2025-14992) https://t.co/qOHPfzTb0J

    @vuldb

    22 Dec 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 HIGH-severity alert: Tenda AC18 routers (15.03.05.05) are vulnerable to a stack-based buffer overflow (CVE-2025-14992). Remote code execution is possible—exploit is public! Patch or mitigate ASAP. https://t.co/brxWBoJAEK... https://t.co/dDTrJhcjp3

    @offseq

    21 Dec 2025

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🟠 CVE-2025-14992 - High A security vulnerability has been detected in Tenda AC18 15.03.05.05. The impacted element is the function strcpy of the file /goform/GetParentControlInfo of the component HTTP Request Handle... https://t.co/XIJGAASHPN https://t.co/gz8ftcDRYP

    @TheHackerWire

    21 Dec 2025

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. [CVE-2025-14992: HIGH] Critical security alert: Vulnerability in Tenda AC18 (15.03.05.05) found in HTTP Request Handler could lead to stack-based buffer overflow, allowing remote exploitation. Action recomme...#cve,CVE-2025-14992,#cybersecurity https://t.co/vqBuu18TSw https://t.c

    @CveFindCom

    21 Dec 2025

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations