CVE-2025-10120
published 2025-09-09CVE-2025-10120: A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /goform/GetParentControlInfo. The…
high7.4CVSS 4.0
AVNACLATNPRLUINVCHVIHVAHSCNSINSANEPCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /goform/GetParentControlInfo. The manipulation of the argument mac results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | ac20 | — | — |
| tenda | ac20 | — | — |
| tenda | ac20 | — | — |
| tenda | ac20 | — | — |
| tenda | ac20 | — | — |
| tenda | ac20 | — | — |
| tenda | ac20 | — | — |
| tenda | ac20 | — | — |
| tenda | ac20 | — | — |
| tenda | ac20 | — | — |
| tenda | ac20 | — | — |
| tenda | ac20 | — | — |
| tenda | ac20 | — | — |
| tenda | ac20_firmware | <= 16.03.08.12 | — |