PT-2026-28687 · Tenda · Tenda Ac6
Wxhwxhwxh_Mie
·
Published
2026-03-27
·
Updated
2026-03-27
·
CVE-2026-4961
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda AC6 version 15.03.05.16
Description
A flaw exists in the Tenda AC6 device that allows for a stack-based buffer overflow. This occurs through the manipulation of the
PPPOEPassword argument within the formQuickIndex function, located in the file /goform/QuickIndex, via a POST request handler. The issue is remotely exploitable and a public exploit is available.Recommendations
Update to a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting access to the /goform/QuickIndex file.
Avoid using the
PPPOEPassword parameter in the affected function until the issue is resolved.Exploit
Fix
Memory Corruption
Buffer Overflow
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda Ac6