CVE detail
CVE-2025-15047
A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of the component HTTP Request Handler. Performing a manipulation of the argument Username results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://www.tenda.com.cn/www.tenda.com.cn
No excerpt available.
Third Party Advisorywww.tenda.com.cnDec 23, 2025, 10:15 PM - https://vuldb.com/?submit.720884vuldb.com
No excerpt available.
Exploitvuldb.comDec 23, 2025, 10:15 PM - https://vuldb.com/?id.337852vuldb.com
No excerpt available.
Exploitvuldb.comDec 23, 2025, 10:15 PM - https://vuldb.com/?ctiid.337852vuldb.com
No excerpt available.
Exploitvuldb.comDec 23, 2025, 10:15 PM No excerpt available.
Exploitgithub.comDec 23, 2025, 10:15 PM- https://github.com/z472421519/BinaryAudit/blob/main/PoC/BOF/Tenda_WH450/PPTPDClient/PPTPDClient.mdgithub.com
No excerpt available.
Exploitgithub.comDec 23, 2025, 10:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- z472421519/BinaryAuditHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 25, 2026, 6:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-15180CVSS 7.3 · High
A vulnerability was identified in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/webExcptypemanFilte of the component HTTP Request Handler.…
- CVE-2025-15179CVSS 7.3 · High
A vulnerability was determined in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/qossetting. This manipulation of the argument page causes stack-based b…
- CVE-2025-15178CVSS 7.3 · High
A vulnerability was found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/VirtualSer of the component HTTP Request Handler. The manipulatio…
- CVE-2025-15177CVSS 7.3 · High
A vulnerability has been found in Tenda WH450 1.0.0.18. This vulnerability affects unknown code of the file /goform/SetIpBind of the component HTTP Request Handler. The manipulati…
- CVE-2025-15164CVSS 7.3 · High
A security flaw has been discovered in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/SafeMacFilter. The manipulation of the argument page results in stack…
- CVE-2025-15163CVSS 7.3 · High
A vulnerability was identified in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/SafeEmailFilter. The manipulation of the argument…