cbcvebase.
CVE-2025-10815
published 2025-09-22

CVE-2025-10815: A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this issue is the function strcpy of the file /goform/SetPptpServerCfg of the…

PriorityP264high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.77%
51.4th percentile
A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this issue is the function strcpy of the file /goform/SetPptpServerCfg of the component HTTP POST Request Handler. Such manipulation of the argument startIp leads to buffer overflow. The attack can be launched remotely. The exploit is publicly available and might be used.

Affected

14 ranges
VendorProductVersion rangeFixed in
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20
tendaac20_firmware<= 16.03.08.12

Detection & IOCsextracted from sources · hover to see the quote

path/goform/SetPptpServerCfg
urlhttps://github.com/CH13hh/tmp_store_cc/blob/main/AC7formSetPPTPServer/formSetPPTPServer.md
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Tenda AC7 SetPptpServerCfg Buffer Overflow Attempt (CVE-2025-3346, CVE-2025-10803, CVE-2025-10815)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:24; content:"/goform/SetPptpServerCfg"; fast_pattern; http.request_body; content:"startIp|3d|"; content:"endIp|3d|"; pcre:"/(?:start|end)Ip\x3d.{200}/P"; reference:url,github.com/CH13hh/tmp_store_cc/blob/main/AC7formSetPPTPServer/formSetPPTPServer.md; reference:cve,2025-3346; reference:cve,2025-10803; reference:cve,2025-10815; classtype:attempted-admin; sid:2061337; rev:1; metadata:affected_product Tenda, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_04_07, cve CVE_2025_3346, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, updated_at 2025_04_07, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
  • Exploit targets HTTP POST requests to /goform/SetPptpServerCfg with oversized startIp and/or endIp parameters (>=200 chars) to trigger a stack buffer overflow via strcpy.
  • The URI path is exactly 24 bytes (/goform/SetPptpServerCfg); use a fixed bsize match to reduce false positives.
  • Attack is plaintext HTTP only (no TLS); deploy detection at perimeter and internal network boundaries.
  • Maps to MITRE ATT&CK T1190 (Exploit Public-Facing Application) under tactic TA0001 (Initial Access).
  • ·The Snort/Suricata rule (ET sid:2061337) covers three related CVEs (CVE-2025-3346, CVE-2025-10803, CVE-2025-10815) across Tenda AC7/AC20 variants; tune or split the rule if per-CVE fidelity is required.
  • ·A public exploit PoC is already available; treat any matching traffic as high-confidence exploitation attempt rather than scanning.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.