Tenda AC9 Stack Overflow Vulnerability in AdvSetMacMtuWan Leading to Remote Code Execution

Vulnerability

A stack overflow vulnerability has been identified in the Tenda AC9 router, specifically in version 1.0 V15.03.05.14_multi. The vulnerability arises in the mac parameter of the /goform/AdvSetMacMtuWan endpoint, allowing for remote arbitrary code execution.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected device, potentially leading to unauthorized access or control over the router.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
9.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.