CVE-2025-51085: Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/SetSysTimeCfg.
Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/SetSysTimeCfg. The manipulation of the argument `timeZone` and `timeType` leads to stack-based buffer overflow.
Security readout for executives and security teams
Plain-English summary
This CVE describes a remotely reachable crash risk in Tenda AC8V4 firmware V16.03.34.06. A malformed system time configuration request can trigger a stack overflow, with the published CVSS vector indicating low availability impact and no confirmed confidentiality or integrity impact.
Executive priority
Treat this as a targeted router hardening item, not a crisis. Prioritize internet-exposed or business-critical sites first because exploitation could disrupt device availability, but supplied sources do not support claims of data theft or active exploitation.
Technical view
The issue is a CWE-121 stack-based buffer overflow in /goform/SetSysTimeCfg. The supplied description names the timeZone and timeType arguments as the trigger. CVSS 3.1 is 5.3: network reachable, low complexity, no privileges, no user interaction, unchanged scope, availability low.
Likely exposure
Organizations are exposed if they operate Tenda AC8V4 devices running firmware V16.03.34.06, especially where the router management surface is reachable from untrusted networks. The CVE affected-products fields are incomplete, so confirm models and firmware directly from device inventory.
Exploitation context
The source bundle does not show CISA KEV listing or active exploitation evidence. It does show a public GitHub reference, but the provided data is insufficient to assess exploit reliability or real-world abuse.
Researcher notes
The affected metadata is weak: vendor, product, versions, and CPEs are listed as n/a, while the narrative identifies Tenda AC8V4 V16.03.34.06. Avoid broad product assertions without vendor confirmation. No patch details are present in the supplied sources.
Mitigation direction
Inventory Tenda AC8V4 devices and confirm firmware versions.
Check Tenda guidance for fixed firmware or vendor-approved mitigation.
Disable remote administration from the internet where possible.
Restrict management access to trusted administrative networks only.
Monitor affected routers for unexpected restarts or management-service instability.
Validation and detection
Confirm whether any device runs AC8V4 firmware V16.03.34.06.
Review firewall rules for exposed router management interfaces.
Check asset records against the CVE title and description, not only CPE data.
Verify vendor advisory status before declaring remediation complete.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-121: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-121 · source CWE mapping
Stack-based Buffer Overflow
Stack-based Buffer Overflow represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.