VulnerabilityAnalyzed
CVE-2025-7747
A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9.
HIGH 7.4EPSS 0.82%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.82%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler. The manipulation of the argument PPW leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
- CVSS 4.0
- 7.4 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.82% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-120
- Affected
- tenda/fh451 firmware
- Source
- cna@vuldb.com
References
- https://github.com/zezhifu1/cve_report/blob/main/FH451/fromWizardHandle.mdExploit, Third Party Advisory
- https://github.com/zezhifu1/cve_report/blob/main/FH451/fromWizardHandle.md#payloadExploit, Third Party Advisory
- https://vuldb.com/?ctiid.316737Permissions Required, VDB Entry
- https://vuldb.com/?id.316737Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.615487Third Party Advisory, VDB Entry
- https://www.tenda.com.cn/Product
- https://github.com/zezhifu1/cve_report/blob/main/FH451/fromWizardHandle.mdExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.