CVE-2025-7544Active Exploitation(tenda / ac1206)

MEDIUMCVSS 7.4 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for tenda ac1206 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac1206
  • ac1206_firmware

Threat summary

  • Active exploitation appears in 9 classified signals
  • Exploit tooling references are present in monitored signal
  • 10 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 9 signals
  • Exploit tool or code specified in 1 signal
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-03-04); latest day: 1
  • 10 total mentions across 8 days

Affected systems

Vendors
Products
ac1206ac1206_firmware

2 versions affected across 2 products

Deep dive

Activity timeline10 mentions / 8d
01223Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Mentions · 2026-03-03: 1Mentions · 2026-03-04: 3Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-08: 1Mentions · 2026-08-14: 1Exploit Tool / Code · 2026-03-04: 1Active Exploitation · 2026-03-01: 1Active Exploitation · 2026-03-03: 1Active Exploitation · 2026-03-04: 3Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-03-06: 1Active Exploitation · 2026-03-08: 1Active Exploitation · 2026-08-14: 1Technical Details · 2026-03-01: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 1Technical Details · 2026-08-14: 102-2803-0103-0303-0403-0503-0603-0808-14
Signal classification2 categories
Active Exploitation
990.0%
General
110.0%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-02-281
General1
2026-03-011
Active Exploitation1
2026-03-031
Active Exploitation1
2026-03-043
Active Exploitation3
2026-03-051
Active Exploitation1
2026-03-061
Active Exploitation1
2026-03-081
Active Exploitation1
2026-08-141
Active Exploitation1
Full discourse10 posts
  • blackorbird@blackorbird
    General

    Zerobot + CVE-2025-7544 & CVE-2025-68613 https://www.akamai.com/blog/security-research/2026/feb/zerobot-malware-targets-n8n-automation-platform https://t.co/dkvMy58yum

    Post summary

    The post references two CVE identifiers and a blog link but offers no further technical or operational details.

    1602872.7K
    40.2K followersView on X
  • Mr. OS@ksg93rd
    Active Exploitation

    #Malware_analysis 1⃣ Zerobot Malware https://www.akamai.com/blog/security-research/2026/feb/zerobot-malware-targets-n8n-automation-platform // Exploitation of command injection vulnerabilities CVE-2025-7544, CVE-2025-68613 against Tenda AC1206 routers and the n8n automation platform 2⃣ Archive*org Stego Delivers Remcos and AsyncRAT https://www.derp.ca/research/archive-org-stego-campaign // The operator hides .NET injector DLLs inside 4K wallpaper JPEGs using steganography 3⃣ Hydra and Saiga malware https://www.vmray.com/hydra-saiga-covert-espionage-and-infiltration-of-critical-utilities/ 4⃣ Inside a fake Google security check that becomes a browser RAT https://www.malwarebytes.com/blog/privacy/2026/02/inside-a-fake-google-security-check-that-becomes-a-browser-rat 5⃣ Moonrise RAT https://evalian.co.uk/inside-a-new-malware-trojan-moonrise // examines the malware’s WebSocket C&C architecture, JSON-based tasking model, and surveillance capabilities to understand its operational risk

    Post summary

    The blog post reports that Zerobot malware actively exploits CVE-2025-7544 and CVE-2025-68613 via command injection on Tenda AC1206 routers and the n8n automation platform.

    06021101.9K
    3.1K followersView on X
  • Oscar@OscarOPS
    Active Exploitation

    Zerobot is back with an active campaign chaining CVE-2025-7544 in Tenda AC1206 routers and CVE-2025-68613 in n8n workflow automation. If you run either in production, check for compromise now.

    Post summary

    The text reports that CVE-2025-7544 and CVE-2025-68613 are actively being exploited in a live attack campaign, urging users to verify potential compromise.

    10020112
    25 followersView on X
  • Threat Intelligence@threatintel
    Active Exploitation

    #ThreatProtection New #Zerobot (#Mirai variant) activity: CVE-2025-7544 (Tenda AC1206) and CVE-2025-68613 (n8n) are being exploited in the wild. https://www.broadcom.com/support/security-center/protection-bulletin/zerobot-campaign-exploits-cve-2025-7544-and-cve-2025-68613 #malware #botnet

    Post summary

    The post reports that CVE-2025-7544 and CVE-2025-68613 are actively exploited in the wild by the Zerobot botnet.

    010201.6K
    114.4K followersView on X
  • Cloud Virtues@CloudVirtues
    Active Exploitation

    Zerobot Campaign Exploits CVE-2025-7544 and CVE-2025-68613 https://dy.si/ZDfyG3 https://t.co/JJQmoFrphV

    Post summary

    The post announces that Zerobot is actively exploiting CVE-2025-7544 and CVE-2025-68613 in a campaign, without providing detailed evidence or mitigation advice.

    00020121
    12 followersView on X
  • Dr. Siraj Dokadia@SirajD_Official
    Active Exploitation

    Zerobot Campaign Exploits CVE-2025-7544 and CVE-2025-68613 https://dy.si/9TriR https://t.co/XNXqgJlKoZ

    Post summary

    The tweet reports that the Zerobot Campaign exploited CVE-2025-7544 and CVE-2025-68613, but provides no technical details, PoC, or mitigation information.

    0001077
    15 followersView on X
  • vertexelite@liyonramesh
    Active Exploitation

    My router got hit by Mirai. Jan 2026. I opened Ghidra instead of replacing it. Result: CVE-2025-7544 (CVSS 8.8), telnet RCE, full shell — affecting Dialog/SLT routers across Sri Lanka. CERT/CC VU#213560 https://vertexelite.org #CVE #IoT #SriLanka

    Post summary

    The post reports a real‑world Mirai infection that exploited CVE‑2025‑7544, a telnet‑based RCE in Dialog/SLT routers, providing technical details but no fix or PoC.

    0000047
    12 followersView on X
  • Mayur Kulkarni@mayurk21
    Active Exploitation

    Zerobot Campaign Exploits CVE-2025-7544 and CVE-2025-68613 https://dy.si/moXmkR https://t.co/a3HWm4xoEd

    Post summary

    The post announces that the Zerobot campaign is actively exploiting CVE‑2025‑7544 and CVE‑2025‑68613, but provides no PoC, exploit code, or mitigation details.

    00000128
    21 followersView on X
  • Jason Wilcox@IdentityJason
    Active Exploitation

    Zerobot Campaign Exploits CVE-2025-7544 and CVE-2025-68613 https://dy.si/BCKqKE2 https://t.co/A4AzTkblX5

    Post summary

    The tweet announces that the Zerobot campaign is actively exploiting CVE-2025-7544 and CVE-2025-68613, with links provided but no further details on PoC, tool, or mitigation.

    00000101
    97 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 Zerobot Botnet Exploits Tenda AC1206 + n8n RCE Bugs to Drop Mirai Payloads and Steal Dev Secrets Akamai SIRT observed Zerobot actively exploiting CVE-2025-7544 (Tenda AC1206 /goform/setMacFilterCfg buffer overflow) and CVE-2025-68613 (n8n expression-eval RCE) to execute code, drop a shell script (http://tol.sh), fetch payloads from Vercel-hosted infrastructure, and enroll devices into a Mirai-style botnet. Beyond DDoS/botnet control, the campaign also pulls a multi-stage infostealer toolkit targeting browser creds, SSH keys, and Git repositories—turning “router/n8n exposure” into developer-data theft and lateral-movement risk. 🕷️ Malware: Zerobot (Mirai-based botnet) 🎯 Target: Global/IoT Routers & Workflow Automation (Tenda AC1206, n8n) #️⃣ Category: #Malware #Vulnerability #CyberCrime #BlueTeam 🔗 URL: https://cyberpress.org/zerobot-exploits-tenda-vulnerability/

    Post summary

    Zerobot botnet is actively exploiting CVE‑2025‑7544 and CVE‑2025‑68613 to drop Mirai‑style payloads and steal developer credentials, demonstrating real‑world exploitation of these vulnerabilities.

    0000097
    261 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac1206---
OStendaac1206_firmware15.03.06.23--

Explore more