
🚨 HIGH SEVERITY: CVE-2025-15178 (CVSS 7.2) Stack-based buffer overflow in Tenda WH450 router (v1[.]0[.]0[.]18). Remote exploitation via /goform/VirtualSer endpoint. Public exploit available. Patch immediately! #CVE #PatchNow https://t.co/fcZlWWSPVT
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
A vulnerability was found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/VirtualSer of the component HTTP Request Handler. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
2 versions affected across 2 products

🚨 HIGH SEVERITY: CVE-2025-15178 (CVSS 7.2) Stack-based buffer overflow in Tenda WH450 router (v1[.]0[.]0[.]18). Remote exploitation via /goform/VirtualSer endpoint. Public exploit available. Patch immediately! #CVE #PatchNow https://t.co/fcZlWWSPVT
2 of 2 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| HW | tenda | wh450 | - | - | - |
| OS | tenda | wh450_firmware | 1.0.0.18 | - | - |