CVE-2025-5839
Tenda AC9 POST Request AdvSetLanip fromadvsetlanip buffer overflow
CVSS v3
8.8
HIGH
EPSS Score
1.0 %
exploit probability, as of 2026-10-11
CISA KEV
No
known exploited
Exploitation
poc
SSVC status
Affected and fixed versions
Neither OSV.dev nor the vendor advisories we read list affected versions for CVE-2025-5839 yet.
Description
A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Handler. The manipulation of the argument lanMask leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Technical details
- CVSS v3 Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Published
- 2025-06-07
- Last Modified
- 2025-06-09
Frequently asked questions
What is CVE-2025-5839?
A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Handler. The manipulation of the argument lanMask leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Is CVE-2025-5839 actively exploited?
A proof-of-concept exploit exists for CVE-2025-5839, but active exploitation has not been confirmed at this time.
What is the CVSS score for CVE-2025-5839?
CVE-2025-5839 has a CVSS v3 base score of 8.8 (HIGH severity), with vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Running Tenda AC9? Hear about its next vulnerability
CVE Watch matches each new CVE to the vendors and products you list (vendor and product, not the version) and puts it in your alerts with its KEV and EPSS status.
Already have an account? Open CVE Watch
No credit card required · 50 free checks/month · Free API key
Go further
- Following what attackers exploit right now? The CISA KEV additions of the month, with their patch deadlines.
- Running this software? CVE Watch alerts you to new vulnerabilities in your products.
Related vulnerabilities
Same product first, then the same vendor advisory and the same publication week.
- CVE-2025-49113KEVsame weekroundcubemail: Remote Code Execution in Roundcube via Unvalidated _from Parameter
- CVE-2025-5086KEVsame week
- CVE-2025-5419KEVsame week
- CVE-2025-47827KEVsame week
- CVE-2025-21479KEVsame weekIncorrect Authorization in Graphics
- CVE-2025-21480KEVsame week
- CVE-2025-44148same week
- CVE-2025-41646same week