Severity
8.7HIGH
EPSS
1.0%
top 22.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 18
Latest updateMay 19

Description

A vulnerability was found in Tenda A15 15.13.07.09/15.13.07.13. It has been classified as critical. This affects an unknown part of the file /goform/multimodalAdd of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5tenda/a1515.13.07.09, 15.13.07.13+1
NVDtenda/a15_firmware15.13.07.09, 15.13.07.13+1

🔴Vulnerability Details

2
GHSA
GHSA-xg7m-xvh7-g9px: A vulnerability was found in Tenda A15 152025-05-19
CVEList
Tenda A15 HTTP POST Request multimodalAdd buffer overflow2025-05-18