Severity
7.4HIGH
EPSS
0.3%
top 49.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 22

Description

A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this issue is the function strcpy of the file /goform/SetPptpServerCfg of the component HTTP POST Request Handler. Such manipulation of the argument startIp leads to buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

NVDtenda/ac20_firmware16.03.08.12
CVEListV5tenda/ac2013 versions+12

🔴Vulnerability Details

2
GHSA
GHSA-6mx8-2wj2-45ww: A vulnerability was identified in Tenda AC20 up to 162025-09-22
CVEList
Tenda AC20 HTTP POST Request SetPptpServerCfg strcpy buffer overflow2025-09-22

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS Tenda AC7 SetPptpServerCfg Buffer Overflow Attempt (CVE-2025-3346, CVE-2025-10803, CVE-2025-10815)2025-04-07