Tenda AC20是中国腾达(Tenda)公司的一款无线路由器。 Tenda AC20 16.03.08.12版本存在安全漏洞,该漏洞源于/goform/setMacFilterCfg文件中sub_46A2AC函数对参数deviceList处理不当导致栈缓冲区溢出。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-9023 | 8.8 HIGH | Tenda AC7/AC18 SetLEDCfg formSetSchedLed buffer overflow |
| CVE-2025-9007 | 8.8 HIGH | Tenda CH22 editFileName formeditFileName buffer overflow |
| CVE-2025-9006 | 8.8 HIGH | Tenda CH22 delFileName formdelFileName buffer overflow |
No comments yet