PT-2025-47105 · Tenda · Tenda Ac20

·

CVE-2025-13258

·

Published

2025-11-16

·

Updated

2025-11-22

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda AC20 versions up to 16.03.08.12
Description A buffer overflow exists in the Tenda AC20 router. The issue is located in an unknown function within the /goform/WifiExtraSet file. Manipulation of the wpapsk crypto argument can trigger the overflow, allowing for remote code execution. The exploit for this issue is publicly available.
Recommendations Versions up to 16.03.08.12 should be updated to a newer, secure version as soon as possible. As a temporary workaround, restrict access to the /goform/WifiExtraSet endpoint to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00089
CVE-2025-13258

Affected Products

Tenda Ac20