cvedb.io
CVE-2025-63835
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2025-11-10T17:15:35.960 · Last modified 2026-06-17T09:53:31.340

Summary

A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attackers can exploit this vulnerability by sending oversized data to the guestSsid parameter, leading to denial of service (device crash) or potential remote code execution.

Affected products

tenda — ac18_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when tenda ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.