PT-2025-43396 · Tenda · Tenda Ac6

Published

2025-10-11

·

Updated

2025-11-19

·

CVE-2025-60339

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Tenda AC6 version 15.03.06.50
Description Multiple buffer overflow vulnerabilities exist in the openSchedWifi function of the Tenda AC6 router. These flaws allow attackers to cause a Denial of Service (DoS) by injecting a crafted payload into the schedStartTime and schedEndTime parameters. The vulnerability involves writing data beyond the allocated buffer in memory. Exploitation can be achieved remotely by sending a specially crafted HTTP request.
Recommendations Update to a newer version of the Tenda AC6 router that contains a fix for this vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-13546
CVE-2025-60339

Affected Products

Tenda Ac6