CVE-2025-67073 Details
Description
A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of service and possibly code execution by sending a post request with a crafted payload (field `serviceName`) to /goform/AdvSetMacMtuWan.
A buffer overflow vulnerability has been identified in the Tenda AC10V4.0 router, specifically in version V16.03.10.20. The issue resides in the HTTP daemon within the 'fromAdvSetMacMtuWan' function. Remote attackers can exploit this vulnerability by sending a POST request with a crafted payload in the 'serviceName' field to the '/goform/AdvSetMacMtuWan' endpoint. This exploitation can lead to a denial-of-service condition and potentially allow for arbitrary code execution.
It is recommended to limit the number of bytes read into the buffer for the 'serviceName' field in the vulnerable function.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/johnathanhuutri/CVEReport/tree/master/CVE-2025-67073 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| tenda ac10 firmware | 16.03.10.20 |
CPE
Remediation
| |
| tenda ac10 | 4.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 2, 2026 | Initial Analysis | [email protected] |
| Dec 17, 2025 | New CVE Received | [email protected] |
| Dec 17, 2025 | CVE Modified | CISA-ADP |