PT-2025-43398 · Tenda · Tenda Ac6 V2.0

Published

2025-10-11

·

Updated

2025-11-19

·

CVE-2025-60341

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Tenda AC6 versions 15.03.06.50
Description The Tenda AC6 V2.0 firmware contains a stack overflow issue in the fast setting wifi set function. This flaw is triggered by a crafted input to the ssid parameter, potentially allowing an attacker to cause a Denial of Service (DoS). The vulnerability can be exploited remotely by sending a specially crafted HTTP request. The stack overflow occurs due to data being written beyond the bounds of an allocated memory buffer.
Recommendations Update to a newer version of the firmware that addresses this vulnerability. As a temporary workaround, consider restricting access to the fast setting wifi set function until a patch is available.

Exploit

Fix

DoS

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-13548
CVE-2025-60341

Affected Products

Tenda Ac6 V2.0