A vulnerability was identified in Tenda AC9 and AC15 15.03.05.14/15.03.05.18. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
History

Fri, 19 Sep 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Tenda ac15 Firmware
Tenda ac9 Firmware
CPEs cpe:2.3:h:tenda:ac15:-:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac9:1.0:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac15_firmware:15.03.05.18:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac9_firmware:15.03.05.14:*:*:*:*:*:*:*
Vendors & Products Tenda ac15 Firmware
Tenda ac9 Firmware

Wed, 17 Sep 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda ac15
Tenda ac9
Vendors & Products Tenda
Tenda ac15
Tenda ac9

Mon, 15 Sep 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 15 Sep 2025 11:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Tenda AC9 and AC15 15.03.05.14/15.03.05.18. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
Title Tenda AC9/AC15 exeCommand formexeCommand buffer overflow
Weaknesses CWE-119
CWE-120
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-09-15T11:32:07.435Z

Updated: 2025-09-15T11:40:44.495Z

Reserved: 2025-09-14T15:42:18.331Z

Link: CVE-2025-10443

cve-icon Vulnrichment

Updated: 2025-09-15T11:40:41.343Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-15T12:15:32.690

Modified: 2025-09-19T19:22:53.663

Link: CVE-2025-10443

cve-icon Redhat

No data.