CVE-2025-63835

Source
https://cve.org/CVERecord?id=CVE-2025-63835
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-63835.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-63835
Published
2025-11-10T17:15:35.960Z
Modified
2026-03-13T03:40:55.494621Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attackers can exploit this vulnerability by sending oversized data to the guestSsid parameter, leading to denial of service (device crash) or potential remote code execution.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-63835.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "15.03.05.05"
            }
        ]
    }
]