From c6d66c12d9f897575c6e2ae303e2423e1d7421b5 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 9 Jun 2025 00:32:11 +0000 Subject: [PATCH] Publish Advisories GHSA-3c2j-gj86-4xvq GHSA-4287-9xx6-3794 GHSA-629p-hwcg-x88h GHSA-rqj6-6f2c-2g2c --- .../GHSA-3c2j-gj86-4xvq.json | 56 +++++++++++++++++++ .../GHSA-4287-9xx6-3794.json | 56 +++++++++++++++++++ .../GHSA-629p-hwcg-x88h.json | 56 +++++++++++++++++++ .../GHSA-rqj6-6f2c-2g2c.json | 56 +++++++++++++++++++ 4 files changed, 224 insertions(+) create mode 100644 advisories/unreviewed/2025/06/GHSA-3c2j-gj86-4xvq/GHSA-3c2j-gj86-4xvq.json create mode 100644 advisories/unreviewed/2025/06/GHSA-4287-9xx6-3794/GHSA-4287-9xx6-3794.json create mode 100644 advisories/unreviewed/2025/06/GHSA-629p-hwcg-x88h/GHSA-629p-hwcg-x88h.json create mode 100644 advisories/unreviewed/2025/06/GHSA-rqj6-6f2c-2g2c/GHSA-rqj6-6f2c-2g2c.json diff --git a/advisories/unreviewed/2025/06/GHSA-3c2j-gj86-4xvq/GHSA-3c2j-gj86-4xvq.json b/advisories/unreviewed/2025/06/GHSA-3c2j-gj86-4xvq/GHSA-3c2j-gj86-4xvq.json new file mode 100644 index 00000000000..34555e95070 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3c2j-gj86-4xvq/GHSA-3c2j-gj86-4xvq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c2j-gj86-4xvq", + "modified": "2025-06-09T00:30:31Z", + "published": "2025-06-09T00:30:31Z", + "aliases": [ + "CVE-2025-5849" + ], + "details": "A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been classified as critical. This affects the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation of the argument remoteIp leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5849" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/Tenda-AC15-formSetSafeWanWebMan-20adf0aa1185806daab3ebe0036266cb" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311595" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311595" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.591375" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-08T23:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-4287-9xx6-3794/GHSA-4287-9xx6-3794.json b/advisories/unreviewed/2025/06/GHSA-4287-9xx6-3794/GHSA-4287-9xx6-3794.json new file mode 100644 index 00000000000..1c746b53040 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-4287-9xx6-3794/GHSA-4287-9xx6-3794.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4287-9xx6-3794", + "modified": "2025-06-09T00:30:32Z", + "published": "2025-06-09T00:30:31Z", + "aliases": [ + "CVE-2025-5850" + ], + "details": "A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been declared as critical. This vulnerability affects the function formsetschedled of the file /goform/SetLEDCf of the component HTTP POST Request Handler. The manipulation of the argument Time leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5850" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/Tenda-AC15-formsetschedled-20adf0aa118580d984d8fcdb98d9959c" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311596" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311596" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.591376" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-08T23:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-629p-hwcg-x88h/GHSA-629p-hwcg-x88h.json b/advisories/unreviewed/2025/06/GHSA-629p-hwcg-x88h/GHSA-629p-hwcg-x88h.json new file mode 100644 index 00000000000..cb924ac1a4c --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-629p-hwcg-x88h/GHSA-629p-hwcg-x88h.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-629p-hwcg-x88h", + "modified": "2025-06-09T00:30:31Z", + "published": "2025-06-09T00:30:31Z", + "aliases": [ + "CVE-2025-5851" + ], + "details": "A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been rated as critical. This issue affects the function fromadvsetlanip of the file /goform/AdvSetLanip of the component HTTP POST Request Handler. The manipulation of the argument lanMask leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5851" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/Tenda-AC15-fromadvsetlanip-20adf0aa118580a09182c1c5c42079fc" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311597" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311597" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.591384" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T00:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-rqj6-6f2c-2g2c/GHSA-rqj6-6f2c-2g2c.json b/advisories/unreviewed/2025/06/GHSA-rqj6-6f2c-2g2c/GHSA-rqj6-6f2c-2g2c.json new file mode 100644 index 00000000000..eebbe07914a --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-rqj6-6f2c-2g2c/GHSA-rqj6-6f2c-2g2c.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqj6-6f2c-2g2c", + "modified": "2025-06-09T00:30:31Z", + "published": "2025-06-09T00:30:31Z", + "aliases": [ + "CVE-2025-5848" + ], + "details": "A vulnerability was found in Tenda AC15 15.03.05.19_multi and classified as critical. Affected by this issue is the function formSetPPTPUserList of the file /goform/setPptpUserList of the component HTTP POST Request Handler. The manipulation of the argument list leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5848" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/Tenda-AC15-formSetPPTPUserList-20adf0aa118580d080eacb031b89ddc6" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311594" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311594" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.591372" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-08T22:15:21Z" + } +} \ No newline at end of file