Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/bytereaper77/cve-2025-7795
Embedded Systems SecurityIoT SecurityVulnerability AnalysisExploitationWeb Application ExploitationBinary ExploitationArchived
GitHubbytereaper77/cve-2025-7795

CVE-2025-7795

Proof-of-concept exploit for a buffer overflow vulnerability in Tenda routers. Sends crafted unauthenticated POST requests to trigger a crash and confirms impact via ICMP ping checks.

View Repository
281 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-7795 – Tenda Router Buffer Overflow Exploit

Author: Byte Reaper
Telegram: @ByteReaper0
CVE-ID: CVE-2025-7795
Vulnerability Type: Buffer Overflow
Target: Tenda Routers
Exploit: Remote, Unauthenticated


📝 Description

A buffer overflow vulnerability exists in certain Tenda router models. It can be triggered by sending a crafted unauthenticated POST request to the unprotected endpoint:

Save the exploit source code to exploit.c.

Compile the code:

gcc exploit.c argparse.c -o exploit -lcurl

Usage

sudo ./exploit -i <TARGET_IP> [-v]

or

sudo ./exploit -u <TARGET_URL> [-v] -i, --ip    : Target device IP address.

-u, --url   : Full URL to the target (e.g., http://192.168.0.1).

-v, --verbose: Enable verbose output (prints request payloads and details).

Examples Exploit by IP:

sudo ./exploit -i 192.168.1.1 Exploit by URL with verbose mode:

sudo ./exploit -u http://router.local -v 🔍 How It Works The exploit generates a POST payload of the form list=AAAA…, starting at 3500 bytes and increasing by 1000 bytes each iteration (5 iterations total).

It sends the request to /goform/fromP2pListFilter using libcurl.

On HTTP 2xx responses, it reports that the server is still responsive.

On non-2xx responses or connection failures, it issues a ping to the target IP to confirm whether the device has crashed.

⚠️ Disclaimer Authorized testing only: Use this exploit solely in environments where you have explicit permission to test.

Legal notice: Unauthorized use against systems you do not own or have permission to test may be illegal.

Download Tool