Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-63834

A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers can inject malicious payloads that execute when any user visits the router's homepage.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.2%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2025-63834
  • Tenda » Ac18 » Version: N/A
    cpe:2.3:h:tenda:ac18:-
  • Tenda » Ac18 Firmware » Version: 15.03.05.05
    cpe:2.3:o:tenda:ac18_firmware:15.03.05.05


Contact Us

Shodan ® - All rights reserved