CVE-2025-7505

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function frmL7ProtForm of the file /goform/L7Prot of the component HTTP POST Request Handler. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:fh451_firmware:1.0.0.9:*:*:*:*:*:*:*
cpe:2.3:h:tenda:fh451:-:*:*:*:*:*:*:*

History

15 Jul 2025, 17:50

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-12 23:15

Updated : 2025-07-15 17:50


NVD link : CVE-2025-7505

Mitre link : CVE-2025-7505

CVE.ORG link : CVE-2025-7505


JSON object : View

Products Affected

tenda

  • fh451_firmware
  • fh451
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow