A vulnerability classified as critical was found in Tenda AC8 16.03.34.06. The affected element is the function formSetServerConfig of the file /goform/SetServerConfig. Executing manipulation can lead to buffer overflow.
This vulnerability is registered as CVE-2025-11120. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability, which was classified as critical, was found in Tenda AC18 15.03.05.19. This affects an unknown function of the file /goform/WizardHandle. The manipulation of the argument WANT/mtuvalue results in stack-based buffer overflow.
This vulnerability is reported as CVE-2025-11122. The attack can be launched remotely. Moreover, an exploit is present.