Buffer Overflow Vulnerability in Tenda AC9 and AC15 Routers
CVE-2025-10443
Key Information:
Badges
What is CVE-2025-10443?
A buffer overflow vulnerability has been found in the Tenda AC9 and AC15 routers, specifically within the formexeCommand function of the /goform/exeCommand file. An attacker can manipulate the cmdinput parameter, allowing for remote exploitation. This led to concerns about unauthorized access and potential control over the affected devices, as the exploit is publicly accessible. Users are advised to review their security configurations and apply necessary updates to safeguard their networks.
Affected Version(s)
AC15 15.03.05.14
AC15 15.03.05.18
AC9 15.03.05.14
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved