Critical Severity Vulnerability
This vulnerability has been rated as Critical severity. Immediate action is recommended.
CVE-2025-15046
CriticalVulnerability Description
A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/PPTPClient of the component HTTP Request Handler. Such manipulation of the argument netmsk leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Known Affected Software
1 configuration(s) from 1 vendor(s)
cpe:2.3:o:tenda:wh450_firmware:1.0.0.18:*:*:*:*:*:*:*
References & Resources
-
https://github.com/z472421519/BinaryAudit/blob/main/PoC/BOF/Tenda_WH450/PPTPClient/PPTPClient.mdcna@vuldb.com Exploit Third Party Advisory
-
https://github.com/z472421519/BinaryAudit/blob/main/PoC/BOF/Tenda_WH450/PPTPClient/PPTPClient.md#reproducecna@vuldb.com Exploit
-
https://vuldb.com/?ctiid.337851cna@vuldb.com Permissions Required VDB Entry
-
https://vuldb.com/?id.337851cna@vuldb.com Third Party Advisory VDB Entry
-
https://vuldb.com/?submit.720883cna@vuldb.com Third Party Advisory VDB Entry
-
https://www.tenda.com.cn/cna@vuldb.com Product
Severity Details
Key Information
- Published Date
- December 23, 2025
