CVE-2025-4896: Tenda AC10 UserCongratulationsExec buffer overflow
A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/UserCongratulationsExec. The manipulation of the argument getuid leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4896?
CVE-2025-4896 is classified as critical due to its potential for remote exploitation and serious impact on affected systems.
How do I fix CVE-2025-4896?
To fix CVE-2025-4896, users should update their Tenda AC10 firmware to the latest version that addresses this vulnerability.
What are the potential consequences of exploiting CVE-2025-4896?
Exploitation of CVE-2025-4896 could lead to a buffer overflow, allowing attackers to execute arbitrary code on the affected Tenda AC10 device.
Which devices are affected by CVE-2025-4896?
CVE-2025-4896 affects Tenda AC10 routers running firmware version 16.03.10.13.
Can CVE-2025-4896 be exploited remotely?
Yes, CVE-2025-4896 can be exploited remotely, making it crucial for affected users to secure their networks.