PT-2025-43396 · Tenda · Tenda Ac6

Published

2025-10-22

·

Updated

2025-10-23

·

CVE-2025-60339

CVSS v3.1
7.5
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC6 version 15.03.06.50
Description The software contains multiple buffer overflow flaws within the
openSchedWifi
function. An attacker can leverage these to trigger a Denial of Service (DoS) condition by injecting a specially crafted payload into the
schedStartTime
and
schedEndTime
parameters.
Recommendations Update to a newer version that addresses this issue. As a temporary workaround, consider restricting access to the scheduling functionality or disabling the
openSchedWifi()
function until a patch is available.

Exploit

Fix

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2025-60339

Affected Products

Tenda Ac6