Tenda · Tenda Ac1206 · CVE-2025-10432
**Name of the Vulnerable Software and Affected Versions**
Tenda AC1206 version 15.03.06.23
**Description**
A stack-based buffer overflow vulnerability exists in the HTTP Request Handler component of the Tenda AC1206. The vulnerability is located in the `check param changed` function within the `/goform/AdvSetMacMtuWa` file. Manipulation of the `wanMTU` argument can trigger the overflow, allowing for remote exploitation. The exploit for this issue has been made public.
**Recommendations**
Tenda AC1206 version 15.03.06.23: At the moment, there is no information about a newer version that contains a fix for this vulnerability.