{"advisories":[{"id":"EUVD-2025-21279","source":"euvd","title":"A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21279"}],"cve":"CVE-2025-7544","enrichment":{"created":"2025-07-14T22:45:23.900547+00:00","updated":"2025-07-14T22:45:23.900612+00:00","vendors":["tenda","tenda$PRODUCT$ac1206"]},"epss":{"score":0.01671},"mitre":{"cpes":[],"created":"2025-07-13T21:32:07.187000+00:00","description":"A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","metrics":{"cvssV2_0":{"score":9,"vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"},"cvssV3_0":{"score":8.8,"vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"},"cvssV3_1":{"score":8.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"},"cvssV4_0":{"score":8.7,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}},"mitre_repo_path":"cves/2025/7xxx/CVE-2025-7544.json","references":["https://github.com/panda666-888/vuls/blob/main/tenda/ac1206/formSetMacFilterCfg.md","https://github.com/panda666-888/vuls/blob/main/tenda/ac1206/formSetMacFilterCfg.md#poc","https://vuldb.com/?ctiid.316241","https://vuldb.com/?id.316241","https://vuldb.com/?submit.614089","https://www.tenda.com.cn/"],"title":"Tenda AC1206 setMacFilterCfg formSetMacFilterCfg stack-based overflow","updated":"2025-07-15T19:53:10.386000+00:00","vendors":[],"weaknesses":["CWE-119","CWE-121"]},"nvd":{"cpes":["cpe:2.3:h:tenda:ac1206:-:*:*:*:*:*:*:*","cpe:2.3:o:tenda:ac1206_firmware:15.03.06.23:*:*:*:*:*:*:*"],"created":"2025-07-13T22:15:23.693000+00:00","description":"A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","metrics":{"cvssV2_0":{"score":9.0,"vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C"},"cvssV3_0":{},"cvssV3_1":{"score":8.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":7.4,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2025/CVE-2025-7544.json","references":["https://github.com/panda666-888/vuls/blob/main/tenda/ac1206/formSetMacFilterCfg.md","https://github.com/panda666-888/vuls/blob/main/tenda/ac1206/formSetMacFilterCfg.md#poc","https://vuldb.com/?ctiid.316241","https://vuldb.com/?id.316241","https://vuldb.com/?submit.614089","https://www.tenda.com.cn/"],"title":null,"updated":"2026-06-17T10:05:11.307000+00:00","vendors":["tenda","tenda$PRODUCT$ac1206","tenda$PRODUCT$ac1206_firmware"],"weaknesses":["CWE-119","CWE-121"]},"opencve":{"changes":[{"created":"2025-07-13T21:45:00+00:00","data":[{"details":{"new":"A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","old":null},"type":"description"},{"details":{"new":"Tenda AC1206 setMacFilterCfg formSetMacFilterCfg stack-based overflow","old":null},"type":"title"},{"details":{"added":["CWE-119","CWE-121"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://github.com/panda666-888/vuls/blob/main/tenda/ac1206/formSetMacFilterCfg.md","https://github.com/panda666-888/vuls/blob/main/tenda/ac1206/formSetMacFilterCfg.md#poc","https://vuldb.com/?ctiid.316241","https://vuldb.com/?id.316241","https://vuldb.com/?submit.614089","https://www.tenda.com.cn/"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV2_0":{"score":9,"vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"},"cvssV3_0":{"score":8.8,"vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"},"cvssV3_1":{"score":8.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"},"cvssV4_0":{"score":8.7,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"6fd03924-4c87-4ceb-b97e-275ef97857a1"},{"created":"2025-07-14T13:45:00+00:00","data":[{"details":{"added":{"epss":{"score":0.00088}},"removed":{},"updated":{}},"type":"metrics"}],"id":"6b1f5d51-0f4f-442e-8f31-7197dc77a6a4"},{"created":"2025-07-15T20:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"3c77cd63-b8b0-4cb2-8439-960e9bc95a0d"},{"created":"2025-07-16T14:45:00+00:00","data":[{"details":["tenda","tenda$PRODUCT$ac1206","tenda$PRODUCT$ac1206_firmware"],"type":"first_time"},{"details":{"added":["cpe:2.3:h:tenda:ac1206:-:*:*:*:*:*:*:*","cpe:2.3:o:tenda:ac1206_firmware:15.03.06.23:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["tenda","tenda$PRODUCT$ac1206","tenda$PRODUCT$ac1206_firmware"],"removed":[]},"type":"vendors"}],"id":"d2e05955-cbe4-4893-8e02-7a6fe3fc347a"}],"cpes":{"data":["cpe:2.3:h:tenda:ac1206:-:*:*:*:*:*:*:*","cpe:2.3:o:tenda:ac1206_firmware:15.03.06.23:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2025-07-13T21:32:07.187000+00:00","provider":"mitre"},"description":{"data":"A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":9,"vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR"},"provider":"mitre"},"cvssV3_0":{"data":{"score":8.8,"vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"},"provider":"mitre"},"cvssV3_1":{"data":{"score":8.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R"},"provider":"mitre"},"cvssV4_0":{"data":{"score":8.7,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"},"provider":"mitre"},"epss":{"data":{"score":0.01671},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/panda666-888/vuls/blob/main/tenda/ac1206/formSetMacFilterCfg.md","https://github.com/panda666-888/vuls/blob/main/tenda/ac1206/formSetMacFilterCfg.md#poc","https://vuldb.com/?ctiid.316241","https://vuldb.com/?id.316241","https://vuldb.com/?submit.614089","https://www.tenda.com.cn/"],"providers":["mitre","nvd","vulnrichment"]},"title":{"data":"Tenda AC1206 setMacFilterCfg formSetMacFilterCfg stack-based overflow","provider":"mitre"},"updated":{"data":"2025-07-16T14:36:53.967000+00:00","provider":"nvd"},"vendors":{"data":["tenda","tenda$PRODUCT$ac1206","tenda$PRODUCT$ac1206_firmware"],"providers":["nvd","enrichment"]},"weaknesses":{"data":["CWE-119","CWE-121"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2025-07-13T21:32:07.187000+00:00","description":"A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"references":["https://github.com/panda666-888/vuls/blob/main/tenda/ac1206/formSetMacFilterCfg.md"],"title":"Tenda AC1206 setMacFilterCfg formSetMacFilterCfg stack-based overflow","updated":"2025-07-14T16:43:47.889000+00:00","vendors":[],"vulnrichment_repo_path":"2025/7xxx/CVE-2025-7544.json","weaknesses":[]}}