TROYANOSYVIRUS
Retour aux CVEs

CVE-2025-4007

HIGH
8.8

Description

A vulnerability classified as critical was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). Affected by this vulnerability is the function cgidhcpsCfgSet of the file /goform/modules of the component httpd. The manipulation of the argument json leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Details CVE

Score CVSS v3.18.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie4/28/2025
Derniere modification7/30/2025
Sourcenvd
Observations honeypot0

Produits affectes

tenda:i24tenda:i24_firmwaretenda:w12tenda:w12_firmware

Faiblesses (CWE)

CWE-119CWE-121

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.