CVE-2025-9023 | Tenda AC7/AC18 15.03.05.19/15.03.06.44 /goform/SetLEDCfg formSetSchedLed Time buffer overflow
A vulnerability, which was classified as critical, was found in Tenda AC7 and AC18 15.03.05.19/15.03.06.44. Affected is the function formSetSchedLed of the file /goform/SetLEDCfg. The manipulation of the argument Time leads to buffer overflow.
This vulnerability is traded as CVE-2025-9023. It is possible to launch the attack remotely. Furthermore, there is an exploit available.