PoC Index

CVE-2025-10120

HIGH 9.0EPSS 0.8%

A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /goform/GetParentControlInfo. The manipulation of the argument mac results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used. Es wurde eine Schwachstelle in Tenda AC20 bis 16.03.08.12 entdeckt. Betroffen ist die Funktion strcpy der Datei /goform/GetParentControlInfo. Die Manipulation des Arguments mac führt zu buffer overflow. Es ist möglich, den Angriff aus der Ferne durchzuführen. Die Ausnutzung wurde veröffentlicht und kann verwendet werden.

CVSS v4.0
7.4 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
0.83% chance of exploitation in the next 30 days, 55th percentile
Published
2025-09-09

Proof-of-concept exploits (1)

References

Related