VulnerabilityAnalyzed
CVE-2025-15215
A vulnerability was determined in Tenda AC10U 15.03.06.48/15.03.06.49.
HIGH 7.4EPSS 0.69%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability was determined in Tenda AC10U 15.03.06.48/15.03.06.49. This affects the function formSetPPTPUserList of the file /goform/setPptpUserList of the component HTTP POST Request Handler. This manipulation of the argument list causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
- CVSS 4.0
- 7.4 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-120
- Affected
- tenda/ac10u firmware
- Source
- cna@vuldb.com
References
- https://vuldb.com/?ctiid.338600VDB Entry
- https://vuldb.com/?id.338600VDB Entry
- https://vuldb.com/?submit.725365VDB Entry
- https://www.notion.so/Tenda-AC10U-setPptpUserList-2d753a41781f80e8ba6bc37ba6100343?pvs=73Exploit, Third Party Advisory
- https://www.tenda.com.cn/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.