CVE-2025-57220: Input Validation
Published Aug 28, 2025
·Updated
An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09multiTDE01 to escalate privileges to root via a crafted UDP packet.
Affected Software
3 affected components
Tenda AC10>=16.03.10.09_multi_TDE01<=16.03.10.09_multi_TDE01
All of the following
Tenda Ac10 Firmware=16.03.10.09_multi_tde01
Tenda AC10=4.0
Event History
Aug 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-57220?
CVE-2025-57220 has a high severity level due to the potential for privilege escalation to root.
2
How do I fix CVE-2025-57220?
To fix CVE-2025-57220, upgrade the Tenda AC10 firmware to a version that patches the input validation flaw.
3
Which devices are affected by CVE-2025-57220?
CVE-2025-57220 affects Tenda AC10 devices running v16.03.10.09_multi_TDE01 firmware.
4
What type of vulnerability is CVE-2025-57220?
CVE-2025-57220 is an input validation flaw that can be exploited via a crafted UDP packet.
5
Can CVE-2025-57220 be exploited remotely?
Yes, CVE-2025-57220 can be exploited remotely without authentication.