CVE-2024-25751: Tenda AC9 Firmware

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetSysTime function.

Affected products

  • Tenda AC9 Firmware: version 5.03.06.42_multi only

Published 2024-02-26. Last modified 2026-06-17.