CVE-2025-15218: Tenda AC10U POST Request Parameter AdvSetLanip fromadvsetlanip buffer overflow
A weakness has been identified in Tenda AC10U 15.03.06.48/15.03.06.49. Affected by this vulnerability is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Parameter Handler. Executing a manipulation of the argument lanMask can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15218?
CVE-2025-15218 has a high severity due to its potential for triggering buffer overflow vulnerabilities in Tenda AC10U routers.
How do I fix CVE-2025-15218?
To fix CVE-2025-15218, it is recommended to update the firmware of your Tenda AC10U to the latest version released by Tenda.
What components are affected by CVE-2025-15218?
CVE-2025-15218 affects the function fromadvsetlanip found in the POST request parameter handler of the Tenda AC10U firmware.
Who is affected by CVE-2025-15218?
Users of Tenda AC10U running firmware versions 15.03.06.48 and 15.03.06.49 are affected by CVE-2025-15218.
What kind of exploit can occur due to CVE-2025-15218?
Exploitation of CVE-2025-15218 can lead to a buffer overflow, potentially allowing unauthorized access or control over the affected Tenda AC10U device.