High severity8.8NVD Advisory· Published Dec 30, 2025· Updated Jun 17, 2026
CVE-2025-15215
CVE-2025-15215
Description
A vulnerability was determined in Tenda AC10U 15.03.06.48/15.03.06.49. This affects the function formSetPPTPUserList of the file /goform/setPptpUserList of the component HTTP POST Request Handler. This manipulation of the argument list causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected products
4cpe:2.3:o:tenda:ac10u_firmware:15.03.06.48:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:tenda:ac10u_firmware:15.03.06.48:*:*:*:*:*:*:*
- cpe:2.3:o:tenda:ac10u_firmware:15.03.06.49:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- www.notion.so/Tenda-AC10U-setPptpUserList-2d753a41781f80e8ba6bc37ba6100343nvdExploitThird Party Advisory
- vuldb.comnvdVDB Entry
- vuldb.comnvdVDB Entry
- vuldb.comnvdVDB Entry
- www.tenda.com.cnnvdProduct
News mentions
0No linked articles in our index yet.