CVE-2025-7544: Tenda AC1206 — Unauthenticated Stack-Based Buffer Overflow CVSS: 8.8 Published: 2026-02-27 Author: Nirmal Liyon, VertexElite Security Research CVSS 8.8 unauthenticated stack overflow in /goform/setMacFilterCfg, exploited in-the-wild by Mirai Zerobot (Akamai SIRT confirmed) Q: What is CVE-2025-7544? A: An unauthenticated stack-based buffer overflow in the /goform/setMacFilterCfg endpoint of Tenda AC1206 routers (firmware V15.03.06.23), allowing remote code execution without authentication. Discovered by Nirmal Liyon of VertexElite. Q: Is CVE-2025-7544 being exploited in the wild? A: Yes. Akamai SIRT confirmed active exploitation by the Mirai "Zerobot" botnet variant on February 27, 2026. The botnet incorporates this vulnerability as a propagation vector targeting exposed Tenda router management interfaces. Q: What additional findings were documented? A: VertexElite verified that the alleged CVE-2026-11405 backdoor is ABSENT on V15.03.06.23, and documented a new undisclosed /goform/telnet endpoint that invokes TendaTelnet(), opening an authenticated debug telnet surface. Full advisory: https://research.vertexelite.org/advisories/CVE-2025-7544