VYPR
Unrated severityNVD Advisory· Published Sep 15, 2025· Updated Sep 15, 2025

Tenda AC1206 HTTP Request AdvSetMacMtuWa check_param_changed stack-based overflow

CVE-2025-10432

Description

A vulnerability was found in Tenda AC1206 15.03.06.23. This vulnerability affects the function check_param_changed of the file /goform/AdvSetMacMtuWa of the component HTTP Request Handler. Performing manipulation of the argument wanMTU results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

Affected products

2
  • Tenda/AC1206llm-fuzzy
    Range: = 15.03.06.23
  • Tenda/AC1206v5
    Range: 15.03.06.23

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.