CVE-2025-11528: Tenda AC7 Firmware

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability was identified in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/saveAutoQos. The manipulation of the argument enable leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Affected products

  • Tenda AC7 Firmware: version 15.03.06.44 only

Published 2025-10-09. Last modified 2026-10-08.