PT-2025-38541 · Tenda · Tenda Ac6
Faqiadegege
·
Published
2025-05-15
·
Updated
2025-09-19
·
CVE-2025-57528
CVSS v3.1
7.7
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Tenda AC6 versions 15.03.05.16
Description
An issue exists in Tenda AC6 that allows attackers to cause a denial of service. This is achieved by manipulating the
funcname, funcpara1, and funcpara2 parameters within the /SetCfm API endpoint, specifically through the formSetCfm function.Recommendations
Restrict or disable access to the
/SetCfm API endpoint.
Avoid using the funcname, funcpara1, and funcpara2 parameters in the affected API endpoint until the issue is resolved.Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tenda Ac6