CVE-2025-11325
Last modified
CVE-2025-11325 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A security flaw has been discovered in Tenda AC18 15.03.05.19(6318). Affected by this issue is some unknown functionality of the file /goform/fast_setting_pppoe_set. EPSS estimates a 0.72% chance of exploitation in the next 30 days.
Description
A security flaw has been discovered in Tenda AC18 15.03.05.19(6318). Affected by this issue is some unknown functionality of the file /goform/fast_setting_pppoe_set. Performing a manipulation of the argument Username results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ac18 Firmware | 15.03.05.19\(6318\) |
References
- https://github.com/noahze01/IoT-vulnerable/blob/main/Tenda/AC18/fast_setting_pppoe_set.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.327208Permissions Required, VDB Entry
- https://vuldb.com/?id.327208Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.664527Third Party Advisory, VDB Entry
- https://www.tenda.com.cn/Product
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-11325?
How severe is CVE-2025-11325?
How do I fix CVE-2025-11325?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-1132A time-based blind SQL Injection vulnerability exists in the…8.8
- CVE-2025-11320A security vulnerability has been detected in zhuimengshaoni…6.3
- CVE-2025-11321A vulnerability was detected in zhuimengshaonian wisdom-educ…4.3
- CVE-2025-11322A flaw has been found in Mangati NovoSGA up to 2.2.12. The i…3.7
- CVE-2025-11323A vulnerability was determined in UTT 1250GW up to v2v3.2.2-…8.8
- CVE-2025-11324A vulnerability was identified in Tenda AC18 15.03.05.19(631…8.8
- CVE-2025-11326A weakness has been identified in Tenda AC18 15.03.05.19(631…8.8
- CVE-2025-11327A security vulnerability has been detected in Tenda AC18 15.…8.8
- CVE-2025-11328A vulnerability was detected in Tenda AC18 15.03.05.19(6318)…8.8
- CVE-2025-11329A flaw has been found in code-projects Online Course Registr…9.8
- CVE-2025-1133A vulnerability exists in ChurchCRM 5.13.0 and prior that al…7.2
- CVE-2025-11330A vulnerability has been found in PHPGurukul Beauty Parlour …8.8
Are you affected by CVE-2025-11325?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
