VYPR
High severity8.8NVD Advisory· Published Sep 15, 2025· Updated Jun 17, 2026

CVE-2025-10443

CVE-2025-10443

Description

A vulnerability was identified in Tenda AC9 and AC15 15.03.05.14/15.03.05.18. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.

Affected products

6
  • cpe:2.3:o:tenda:ac9_firmware:15.03.05.14:*:*:*:*:*:*:*
  • cpe:2.3:o:tenda:ac15_firmware:15.03.05.18:*:*:*:*:*:*:*
  • Tenda/AC9llm-fuzzy2 versions
    15.03.05.14, 15.03.05.18+ 1 more
    • (no CPE)range: 15.03.05.14, 15.03.05.18
    • (no CPE)range: 15.03.05.14
  • Tenda/AC15llm-fuzzy2 versions
    15.03.05.14, 15.03.05.18+ 1 more
    • (no CPE)range: 15.03.05.14, 15.03.05.18
    • (no CPE)range: 15.03.05.14

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.