PT-2025-43397 · Tenda · Tenda Ac6

Published

2025-10-11

·

Updated

2025-11-19

·

CVE-2025-60340

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Tenda AC6 version 15.03.06.50
Description Multiple buffer overflows exist in the SetClientState function of the Tenda AC6 router. Exploitation of these overflows can lead to a Denial of Service (DoS) by injecting a crafted payload into the limitSpeed, deviceId, and limitSpeedUp parameters. The vulnerability allows a remote attacker to potentially execute arbitrary code or cause a service disruption by sending a specially crafted HTTP request.
Recommendations Update to a newer version of the firmware that addresses this vulnerability. As a temporary workaround, consider disabling the SetClientState function if possible, or restricting access to the affected parameters (limitSpeed, deviceId, and limitSpeedUp).

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-13544
CVE-2025-60340

Affected Products

Tenda Ac6