CVE-2025-14665 CRITICAL
← Quay lại danh sách
Dịch vụ / phần mềm liên quan:
Chưa phân loại — không khớp danh sách dịch vụ/phần mềm đang theo dõi (xem/thêm ở
internal/cve/categories.go), hoặc NVD chưa cung cấp đủ dữ liệu vendor/sản phẩm cho CVE này.
Mô tả
A security flaw has been discovered in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/DhcpListClient of the component HTTP Request Handler. The manipulation of the argument page results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Chi tiết
| Trạng thái | Modified |
| Điểm CVSS | 9.8 (v3.1) |
| Vector CVSS | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Ngày công bố | 22:15 14/12/2025 |
| Ngày cập nhật | 17:10 28/09/2026 |
| Nguồn dữ liệu | nvd |
CWE
Sản phẩm bị ảnh hưởng
| Vendor | Sản phẩm | Khoảng phiên bản |
|---|---|---|
| tenda | wh450_firmware | - |
Tài liệu tham khảo
- [cna@vuldb.com] https://github.com/z472421519/BinaryAudit/blob/main/PoC/BOF/Tenda_WH450/DhcpListClient/DhcpListClient.md (Exploit, Third Party Advisory)
- [cna@vuldb.com] https://github.com/z472421519/BinaryAudit/blob/main/PoC/BOF/Tenda_WH450/DhcpListClient/DhcpListClient.md#reproduce (Exploit, Third Party Advisory)
- [cna@vuldb.com] https://vuldb.com/?ctiid.336397 (Permissions Required, VDB Entry)
- [cna@vuldb.com] https://vuldb.com/?id.336397 (Third Party Advisory, VDB Entry)
- [cna@vuldb.com] https://vuldb.com/?submit.714400 (Third Party Advisory, VDB Entry)
- [cna@vuldb.com] https://vuldb.com/?submit.719220
- [cna@vuldb.com] https://www.tenda.com.cn/ (Product)
Lịch sử thay đổi
| Thời gian | Loại | Trường | Giá trị cũ | Giá trị mới |
|---|---|---|---|---|
| 17:17 28/09/2026 | CREATED | cve | CRITICAL |