A vulnerability was found in Tenda A15 15.13.07.13. Affected is the function fromSetWirelessRepeat of the file /goform/openNetworkGateway. The manipulation of the argument wpapsk_crypto2_4g results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Nov 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Tenda a15 Firmware
CPEs cpe:2.3:h:tenda:a15:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:a15_firmware:15.13.07.13:*:*:*:*:*:*:*
Vendors & Products Tenda a15 Firmware

Tue, 04 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda a15
Vendors & Products Tenda
Tenda a15

Mon, 03 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Nov 2025 07:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Tenda A15 15.13.07.13. Affected is the function fromSetWirelessRepeat of the file /goform/openNetworkGateway. The manipulation of the argument wpapsk_crypto2_4g results in buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
Title Tenda A15 openNetworkGateway fromSetWirelessRepeat buffer overflow
Weaknesses CWE-119
CWE-120
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-11-03T16:06:25.502Z

Reserved: 2025-11-02T14:56:30.250Z

Link: CVE-2025-12619

cve-icon Vulnrichment

Updated: 2025-11-03T16:06:20.051Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-03T07:15:43.140

Modified: 2025-11-05T14:25:59.447

Link: CVE-2025-12619

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-04T16:36:07Z

Weaknesses