CVE-2025-5629: Tenda AC10 HTTP SetPptpServerCfg formSetPPTPServer buffer overflow
A vulnerability, which was classified as critical, was found in Tenda AC10 up to 15.03.06.47. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg of the component HTTP Handler. The manipulation of the argument startIp/endIp leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5629?
CVE-2025-5629 is classified as a critical vulnerability.
How does CVE-2025-5629 affect Tenda AC10 routers?
CVE-2025-5629 affects the PPTP server configuration due to a buffer overflow caused by improper handling of arguments.
What versions of Tenda AC10 are affected by CVE-2025-5629?
CVE-2025-5629 affects Tenda AC10 routers up to version 15.03.06.47.
How can I mitigate CVE-2025-5629?
To mitigate CVE-2025-5629, update your Tenda AC10 router to a version that addresses this vulnerability.
What components are affected by CVE-2025-5629?
CVE-2025-5629 specifically affects the HTTP Handler and its formSetPPTPServer function.