Tenda AC20是中国腾达(Tenda)公司的一款无线路由器。 Tenda AC20 16.03.08.12版本存在安全漏洞,该漏洞源于/goform/formSetVirtualSer文件中save_virtualser_data函数对参数list处理不当导致栈缓冲区溢出。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-9089 | 8.8 HIGH | Tenda AC20 SetIpMacBind sub_48E628 stack-based overflow |
| CVE-2025-9087 | 8.8 HIGH | Tenda AC20 SetNetControlList Endpoint set_qosMib_list stack-based overflow |
No comments yet