CVE List

CVE-2025-11388

Critical 8.8

A vulnerability was identified in Tenda AC15 15.03.05.18. This impacts an unknown function of the file /goform/setNotUpgrade. Such manipulation of the argument newVersion leads to stack-based buffer overflow. The attack may be launched remotely. The exploit is publicly available and might be used.

Published October 7, 2025.

Affected software

Get alerts for Tenda Ac15 Firmware

Reference links