Vulnerability Description
A vulnerability has been found in Tenda AC8 16.03.34.06. This impacts an unknown function of the file /goform/DatabaseIniSet. The manipulation of the argument Time leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ac8 Firmware | 16.03.34.06 |
| Tenda | Ac8 | 4.0 |
Related Weaknesses (CWE)
References
- https://pan.baidu.com/s/11fdpTujKw6Xz0yPE2l4cMwNot Applicable
- https://vuldb.com/?ctiid.330912Permissions RequiredVDB Entry
- https://vuldb.com/?id.330912Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.678887Third Party AdvisoryVDB Entry
- https://www.tenda.com.cn/Product
- https://www.yuque.com/ba1ma0-an29k/nnxoap/ow5xrpw56dqsgtdy?singleDocPermissions Required
FAQ
What is CVE-2025-12618?
CVE-2025-12618 is a vulnerability with a CVSS score of 8.8 (HIGH). A vulnerability has been found in Tenda AC8 16.03.34.06. This impacts an unknown function of the file /goform/DatabaseIniSet. The manipulation of the argument Time leads to buffer overflow. The attack...
How severe is CVE-2025-12618?
CVE-2025-12618 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-12618?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ac8 Firmware, Tenda Ac8.