PT-2025-38541 · Tenda · Tenda Ac6

Faqiadegege

·

Published

2025-05-15

·

Updated

2025-09-19

·

CVE-2025-57528

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Tenda AC6 versions 15.03.05.16
Description An issue exists in Tenda AC6 that allows attackers to cause a denial of service. This is achieved by manipulating the funcname, funcpara1, and funcpara2 parameters within the /SetCfm API endpoint, specifically through the formSetCfm function.
Recommendations Restrict or disable access to the /SetCfm API endpoint. Avoid using the funcname, funcpara1, and funcpara2 parameters in the affected API endpoint until the issue is resolved.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-12453
CVE-2025-57528

Affected Products

Tenda Ac6