CVE List

CVE-2025-11324

Critical 8.8

A vulnerability was identified in Tenda AC18 15.03.05.19(6318). Affected by this vulnerability is an unknown functionality of the file /goform/setNotUpgrade. Such manipulation of the argument newVersion leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

Published October 6, 2025.

Affected software

Get alerts for Tenda Ac18 Firmware

Reference links