Description
A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The impacted element is the function sscanf of the file /goform/PowerSaveSet. The manipulation of the argument powerSavingEn/time/powerSaveDelay/ledCloseType leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Problem types
Product status
16.03.08.1
16.03.08.2
16.03.08.3
16.03.08.4
16.03.08.5
16.03.08.6
16.03.08.7
16.03.08.8
16.03.08.9
16.03.08.10
16.03.08.11
16.03.08.12
Timeline
| 2025-12-30: | Advisory disclosed |
| 2025-12-30: | VulDB entry created |
| 2025-12-30: | VulDB entry last update |
Credits
xuanyu (VulDB User)
References
vuldb.com/?id.338742 (VDB-338742 | Tenda AC20 PowerSaveSet sscanf buffer overflow)
vuldb.com/?ctiid.338742 (VDB-338742 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.726360 (Submit #726360 | Tenda Tenda AC20 V16.03.08.12 Buffer Overflow)
github.com/...k/iot_poc/tree/main/Tenda AC20_Buffer_Overflow
github.com/..._Buffer_Overflow/Tenda AC20_Buffer_Overflow.md
www.tenda.com.cn/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.