---
id: CVE-2025-15218
title: A weakness has been identified in Tenda AC10U 15.03.06.48/15.03.06.49
summary: >-
  A weakness has been identified in Tenda AC10U 15.03.06.48/15.03.06.49.
  Affected by this vulnerability is the function fromadvsetlanip of the file
  /goform/AdvSetLanip of the component POST Request Parameter Handler. Executing
  a manipulati…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: tenda
product: ac10u_firmware
affected:
  - ac10u_firmware = 15.03.06.48
  - ac10u_firmware = 15.03.06.49
published: '2025-12-30'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T17:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15218'
references:
  - url: >-
      https://lavender-bicycle-a5a.notion.site/Tenda-AC10U-fromadvsetlanip-2d753a41781f800c86c8d388a38e8101?source=copy_link
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.338603'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.338603'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.725461'
    label: cna@vuldb.com
  - url: 'https://www.tenda.com.cn/'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.03327
epssPercentile: 0.8823
ingestedAt: '2026-10-05T17:27:45.018Z'
---

## Overview

A weakness has been identified in Tenda AC10U 15.03.06.48/15.03.06.49. Affected by this vulnerability is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Parameter Handler. Executing a manipulation of the argument lanMask can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

## Affected

- `ac10u_firmware = 15.03.06.48`
- `ac10u_firmware = 15.03.06.49`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
