Description
A weakness has been identified in Tenda AC10U 15.03.06.48/15.03.06.49. Affected by this vulnerability is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Parameter Handler. Executing manipulation of the argument lanMask can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be exploited.
Problem types
Product status
15.03.06.49
Timeline
| 2025-12-28: | Advisory disclosed |
| 2025-12-28: | VulDB entry created |
| 2025-12-28: | VulDB entry last update |
Credits
yhryhryhr_miemie (VulDB User)
References
vuldb.com/?id.338603 (VDB-338603 | Tenda AC10U POST Request Parameter AdvSetLanip fromadvsetlanip buffer overflow)
vuldb.com/?ctiid.338603 (VDB-338603 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.725461 (Submit #725461 | Tenda AC10U AC10U v1.0 Firmware V15.03.06.48、AC10U v1.0 Firmware V15.03.06.49 Buffer Overflow)
lavender-bicycle-a5a.notion.site/...38e8101?source=copy_link
www.tenda.com.cn/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.