Tenda AC18 Buffer Overflow Vulnerability in AdvSetLanip Function

Vulnerability

A critical buffer overflow vulnerability has been identified in the Tenda AC18 router, specifically in the version 15.03.05.05. The issue arises in the AdvSetLanip form handler, where the lanMask parameter can be manipulated, leading to a buffer overflow. This vulnerability can be exploited remotely, and a public proof-of-concept exploit is available.

Impact

Exploitation of this vulnerability causes a buffer overflow, which can lead to arbitrary code execution or a denial-of-service condition.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
6.2
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.