A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as critical. This impacts an unknown function of the file /goform/saveAutoQos. This manipulation of the argument enable causes stack-based buffer overflow.
This vulnerability appears as CVE-2025-11123. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability, which was classified as critical, was found in Tenda AC18 15.03.05.19. This affects an unknown function of the file /goform/WizardHandle. The manipulation of the argument WANT/mtuvalue results in stack-based buffer overflow.
This vulnerability is reported as CVE-2025-11122. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability, which was classified as critical, has been found in Tenda AC18 15.03.05.19. The impacted element is an unknown function of the file /goform/AdvSetLanip. The manipulation of the argument lanIp leads to command injection.
This vulnerability is documented as CVE-2025-11121. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability classified as critical was found in Tenda AC8 16.03.34.06. The affected element is the function formSetServerConfig of the file /goform/SetServerConfig. Executing manipulation can lead to buffer overflow.
This vulnerability is registered as CVE-2025-11120. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability classified as problematic has been found in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the file /justines/index.php of the component POST Request Handler. Performing manipulation of the argument from results in cross site scripting.
This vulnerability is cataloged as CVE-2025-11119. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability described as critical has been identified in CodeAstro Student Grading System 1.0. This issue affects some unknown processing of the file /adminLogin.php. Such manipulation of the argument staffId leads to sql injection.
This vulnerability is listed as CVE-2025-11118. The attack may be performed from remote. In addition, an exploit is available.