HIGH
Tenda AC10 ShutdownSetAdd stack-based overflow
Published Apr 3, 2025
8.7
HIGHCVSS 4.0
EPSS 0.92%
Description
A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function ShutdownSetAdd of the file /goform/ShutdownSetAdd. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected products
-
- Version 16.03.10.13StatusaffectedConstraints-
- Version
AND
- 16.03.10.13
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (3)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-15082 Advisory
- https://github.com/LxxxtSec/CVE/blob/main/CVE_1.md broken-linkBroken Link
- https://github.com/LxxxtSec/CVE/blob/main/CVE_1.md#vulnerability-proof-supplement-remote-code-execution-rce broken-linkexploitBroken Link
- https://pan.baidu.com/s/1_zhGlS0fFhz0Pkh8svljjA?pwd=viwq relatedURL Repurposed
- https://vuldb.com/?ctiid.303107 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.303107 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.542437 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.tenda.com.cn/ broken-linkproduct
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-15082 | Advisory | |
| https://github.com/LxxxtSec/CVE/blob/main/CVE_1.md | broken-linkBroken Link | |
| https://github.com/LxxxtSec/CVE/blob/main/CVE_1.md#vulnerability-proof-supplement-remote-code-execution-rce | broken-linkexploitBroken Link | |
| https://pan.baidu.com/s/1_zhGlS0fFhz0Pkh8svljjA?pwd=viwq | relatedURL Repurposed | |
| https://vuldb.com/?ctiid.303107 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.303107 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.542437 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.tenda.com.cn/ | broken-linkproduct |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Apr 3, 2025
Updated Apr 3, 2025
Reserved Apr 3, 2025
Link CVE-2025-3161
CISA Vulnrichment
Updated Apr 3, 2025
ENISA EUVD
EUVD-2025-15082 Assigner VulDB
Published Apr 3, 2025
Updated Apr 3, 2025
Exploited since n/a
Link EUVD-2025-15082