Cyber Posture

CVE-2025-11388

HighPublic PoC

Published: 07 October 2025

Published
07 October 2025
Modified
09 October 2025
KEV Added
Patch
CVSS Score 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0026 49.3th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.

Security Summary

CVE-2025-11388 is a stack-based buffer overflow vulnerability affecting Tenda AC15 routers running firmware version 15.03.05.18. The issue resides in an unknown function within the /goform/setNotUpgrade endpoint, where improper handling of the newVersion argument allows overflow conditions. This flaw, linked to CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-121 (Stack-based Buffer Overflow), was published on 2025-10-07 and carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating high severity.

Remote attackers with low privileges can exploit this vulnerability by manipulating the newVersion parameter in requests to the affected endpoint, potentially leading to arbitrary code execution, data compromise, or denial of service. The low attack complexity and lack of user interaction requirements make it accessible to authenticated users over the network, enabling high impacts on confidentiality, integrity, and availability.

Advisories from VulDB detail the vulnerability and reference a publicly available exploit on GitHub at https://github.com/noahze01/IoT-vulnerable/blob/main/Tenda/AC15/setNotUpgrade.md, which demonstrates the buffer overflow. The vendor's site at https://www.tenda.com.cn/ is listed, though no specific patches or mitigations are detailed in the provided references.

Notable context includes the public availability of the exploit, increasing the risk of real-world abuse against unpatched Tenda AC15 devices.

Details

CWE(s)
CWE-119CWE-121

Affected Products

tenda
ac15 firmware
15.03.05.18

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

Stack-based buffer overflow in the public-facing web interface (/goform/setNotUpgrade) of Tenda AC15 router enables remote exploitation of a public-facing application for initial access, with public PoC available.

References