CVE-2025-29218: Tenda w18e Firmware

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

Affected products

  • Tenda w18e Firmware: version 16.01.0.11 only

Published 2025-03-20. Last modified 2026-06-17.