PT-2025-43400 · Tenda · Tenda Ac6

Published

2025-10-22

·

Updated

2025-11-19

·

CVE-2025-60343

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Tenda AC6 version 15.03.06.50
Description The AdvSetMacMtuWan function in Tenda AC6 version 15.03.06.50 contains multiple buffer overflows. An attacker can exploit this to cause a Denial of Service (DoS) by sending a specially crafted HTTP request. The vulnerability is triggered by injecting a crafted payload into the following parameters: wanMTU, wanSpeed, cloneType, mac, serviceName, serverName, wanMTU2, wanSpeed2, cloneType2, mac2, serviceName2, and serverName2.
Recommendations Update to a newer version that contains a fix for this vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-13580
CVE-2025-60343

Affected Products

Tenda Ac6