CVE-2025-25456
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 15, 2025
Updated: Apr 22, 2025
CWE ID 120
Summary
CVE-2025-25456 is a Buffer Overflow vulnerability affecting the Tenda AC10 V4.0si_V16.03.10.20 firmware. The issue is located in the AdvSetMacMtuWan function, specifically in the mac2 parameter. An attacker can exploit this vulnerability by sending maliciously crafted packets to the affected device, causing it to overflow the buffer and potentially executing arbitrary code. This can lead to unauthorized access, data theft, or denial-of-service attacks. Users are advised to update their firmware as soon as a patch is available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Shenzhen Tenda Technology Co. Ltd