CVE-2025-27129
published 2025-08-20CVE-2025-27129: An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can…
PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.11%
79.8th percentile
An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| craftcms | cms | >= 3.5.0 < 4.16.19 | 4.16.19 |
| craftcms | cms | >= 5.0.0-RC1 < 5.8.23 | 5.8.23 |
| tenda | ac6_firmware | — | — |
| tenda | ac6_v5.0 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 Resolution
ghsa·2026-02-24·CVSS 5.0
CVE-2026-27129 [MEDIUM] CWE-918 Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 Resolution
Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 Resolution
The SSRF validation in Craft CMS’s GraphQL Asset mutation uses `gethostbyname()`, which only resolves IPv4 addresses. When a hostname has only AAAA (IPv6) records, the function returns the hostname string itself, causing the blocklist comparison to always fail and completely bypassing SSRF protection.
This is a bypass of the security fix for CVE-2025-68437 ([GHSA-x27p-wfqw-hfcc](https://github.com/craftcms/cms/security/advisories/GHSA-x27p-wfqw-hfcc)).
## Required Permissions
Exploitation requires GraphQL schema permissions for:
- Edit assets in the `` volume
- Create assets in the `` volume
These permissions may be granted to:
- Authenticated users with appropriate GraphQL schema access
- Public Schema (if misconfig
GHSA
GHSA-ph9v-qvxr-mh9x: An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5
ghsa_unreviewed·2025-08-20
CVE-2025-27129 [CRITICAL] CWE-288 GHSA-ph9v-qvxr-mh9x: An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5
An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability.
No detection rules found.
No public exploits indexed.
Talos
Libbiosig, Tenda, SAIL, PDF XChange, Foxit vulnerabilities
blogs_talos·2025-08-27·CVSS 8.1
[HIGH] Libbiosig, Tenda, SAIL, PDF XChange, Foxit vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed ten vulnerabilities in BioSig Libbiosig, nine in Tenda AC6 Router, eight in SAIL, two in PDF-XChange Editor, and one in a Foxit PDF Reader.
The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy.
For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website.
## Libbiosig vulnerabilities
Discovered by Mark Bereza and Lilith >_> of Cisco Talos.
BioSig is an open source software library for biomedical signal processing. The aim of the BioSig project is to fo
Talos
Libbiosig, Tenda, SAIL, PDF XChange, Foxit vulnerabilities
blogs_talos·2025-08-27·CVSS 8.1
[HIGH] Libbiosig, Tenda, SAIL, PDF XChange, Foxit vulnerabilities
## Libbiosig, Tenda, SAIL, PDF XChange, Foxit vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed ten vulnerabilities in BioSig Libbiosig, nine in Tenda AC6 Router, eight in SAIL, two in PDF-XChange Editor, and one in a Foxit PDF Reader.
The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy .
For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org , and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website .
## Libbiosig vulnerabilities
Discovered by Mark Bereza and Lilith >_> of Cisco Talos.
BioSig is an open source software library for bi
2025-08-20
Published