CVE-2025-10432: Tenda AC1206 HTTP Request AdvSetMacMtuWa check_param_changed stack-based overflow
A vulnerability was found in Tenda AC1206 15.03.06.23. This vulnerability affects the function checkparamchanged of the file /goform/AdvSetMacMtuWa of the component HTTP Request Handler. Performing manipulation of the argument wanMTU results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10432?
CVE-2025-10432 has a high severity rating due to its potential for remote exploitation via stack-based buffer overflow.
How do I fix CVE-2025-10432?
To fix CVE-2025-10432, update the Tenda AC1206 firmware to the latest version provided by the vendor.
What systems are affected by CVE-2025-10432?
CVE-2025-10432 specifically affects the Tenda AC1206 router.
Can CVE-2025-10432 be exploited remotely?
Yes, CVE-2025-10432 can be exploited remotely by manipulating the wanMTU parameter.
What component is vulnerable in CVE-2025-10432?
The vulnerable component in CVE-2025-10432 is the HTTP Request Handler, particularly the check_param_changed function.