High severity8.8NVD Advisory· Published Sep 15, 2025· Updated Jun 17, 2026
CVE-2025-10443
CVE-2025-10443
Description
A vulnerability was identified in Tenda AC9 and AC15 15.03.05.14/15.03.05.18. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
Affected products
6- cpe:2.3:o:tenda:ac9_firmware:15.03.05.14:*:*:*:*:*:*:*
- cpe:2.3:o:tenda:ac15_firmware:15.03.05.18:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- github.com/2664521593/mycve/blob/main/Tenda/Tenda_AC15_AC9_Bof.mdnvdExploitThird Party Advisory
- github.com/2664521593/mycve/blob/main/Tenda/Tenda_AC15_AC9_Bof.mdnvdExploitThird Party Advisory
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
- www.tenda.com.cnnvdProduct
News mentions
0No linked articles in our index yet.