A vulnerability identified as critical has been detected in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function formSysRunCmd of the file /goform/SysRunCmd. This manipulation of the argument getui causes buffer overflow.

This vulnerability appears as CVE-2025-12622. The attack may be initiated remotely. In addition, an exploit is available.