Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-7795 PoC — Tenda FH451 P2pListFilter fromP2pListFilter stack-based overflow

Source
Associated Vulnerability
Title: Tenda FH451 P2pListFilter fromP2pListFilter stack-based overflow (CVE-2025-7795)
Description:A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Description
Proof-of-Concept exploit for CVE-2025-7795 – A buffer overflow vulnerability affecting certain Tenda routers. The exploit sends crafted POST requests to trigger a crash and confirms the impact using ICMP (ping) checks.
Readme
# CVE-2025-7795 – Tenda Router Buffer Overflow Exploit

> **Author**: Byte Reaper  
> **Telegram**: [@ByteReaper0](https://t.me/ByteReaper0)  
> **CVE-ID**: CVE-2025-7795  
> **Vulnerability Type**: Buffer Overflow  
> **Target**: Tenda Routers  
> **Exploit**: Remote, Unauthenticated  

---

## 📝 Description

A **buffer overflow** vulnerability exists in certain Tenda router models. It can be triggered by sending a crafted unauthenticated `POST` request to the unprotected endpoint:

Save the exploit source code to exploit.c.

Compile the code:

gcc exploit.c argparse.c -o exploit -lcurl
##  Usage

sudo ./exploit -i <TARGET_IP> [-v]
# or
sudo ./exploit -u <TARGET_URL> [-v]
-i, --ip    : Target device IP address.

-u, --url   : Full URL to the target (e.g., http://192.168.0.1).

-v, --verbose: Enable verbose output (prints request payloads and details).

Examples
Exploit by IP:

sudo ./exploit -i 192.168.1.1
Exploit by URL with verbose mode:

sudo ./exploit -u http://router.local -v
🔍 How It Works
The exploit generates a POST payload of the form list=AAAA…, starting at 3500 bytes and increasing by 1000 bytes each iteration (5 iterations total).

It sends the request to /goform/fromP2pListFilter using libcurl.

On HTTP 2xx responses, it reports that the server is still responsive.

On non-2xx responses or connection failures, it issues a ping to the target IP to confirm whether the device has crashed.

⚠️ Disclaimer
Authorized testing only: Use this exploit solely in environments where you have explicit permission to test.

Legal notice: Unauthorized use against systems you do not own or have permission to test may be illegal.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →