PT-2025-43879 · Tenda · Tenda Ac6

Z472421519

·

Published

2025-10-27

·

Updated

2025-10-28

·

CVE-2025-12225

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda AC6 version 15.03.06.50
Description A stack-based buffer overflow issue exists in the HTTP Request Handler component of Tenda AC6 version 15.03.06.50. The issue is related to the processing of the /goform/WifiGuestSet file. Manipulation of the shareSpeed argument can trigger the overflow. The attack can be launched remotely, and the exploit has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-13858
CVE-2025-12225

Affected Products

Tenda Ac6