CVE-2025-29137

Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set function, which can cause RCE.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac7_firmware:15.03.06.44:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac7:1.0:*:*:*:*:*:*:*

History

01 Apr 2025, 20:37

Type Values Removed Values Added
CPE cpe:2.3:h:tenda:ac7:1.0:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac7_firmware:15.03.06.44:*:*:*:*:*:*:*
First Time Tenda ac7
Tenda
Tenda ac7 Firmware
References () https://github.com/Raining-101/IOT_cve/blob/main/tenda-ac7form_fast_setting_wifi_set%20timeZone.md - () https://github.com/Raining-101/IOT_cve/blob/main/tenda-ac7form_fast_setting_wifi_set%20timeZone.md - Exploit
Summary
  • (es) Tenda AC7 V1.0 V15.03.06.44 encontró un desbordamiento de búfer causado por el parámetro timeZone en la función form_fast_setting_wifi_set, que puede causar RCE.

19 Mar 2025, 21:15

Type Values Removed Values Added
CWE CWE-120
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

19 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-19 16:15

Updated : 2025-04-01 20:37


NVD link : CVE-2025-29137

Mitre link : CVE-2025-29137

CVE.ORG link : CVE-2025-29137


JSON object : View

Products Affected

tenda

  • ac7
  • ac7_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')