Security Advisory

CVE-2025-11386

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-10-07 10:02:06
Last updated 2026-02-24 06:47:46
Assigner VulDB
State PUBLISHED

Description

A vulnerability was found in Tenda AC15 15.03.05.18. The impacted element is an unknown function of the file /goform/SetDDNSCfg of the component POST Parameter Handler. The manipulation of the argument ddnsEn results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.