ID

VAR-202509-1917


CVE

CVE-2025-57638


DESCRIPTION

Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value.

Trust: 1.0

sources: NVD: CVE-2025-57638

AFFECTED PRODUCTS

vendor:tendamodel:ac9scope:eqversion:1.0

Trust: 1.0

sources: NVD: CVE-2025-57638

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-57638
value: HIGH

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-57638
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: NVD: CVE-2025-57638

PROBLEMTYPE DATA

problemtype:CWE-122

Trust: 1.0

sources: NVD: CVE-2025-57638

EXTERNAL IDS

db:NVDid:CVE-2025-57638

Trust: 1.0

sources: NVD: CVE-2025-57638

REFERENCES

url:https://github.com/glkfc/iot-vulnerability/blob/main/tenda/tenda1.md

Trust: 1.0

sources: NVD: CVE-2025-57638

SOURCES

db:NVDid:CVE-2025-57638

LAST UPDATE DATE

2025-09-25T23:17:20.111000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2025-57638date:2025-09-25T16:09:10.880

SOURCES RELEASE DATE

db:NVDid:CVE-2025-57638date:2025-09-23T19:15:41.437