CVE-2025-30256

CWE-7723 documents3 sources
Severity
7.5HIGH
EPSS
0.1%
top 73.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 20

Description

A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted series of HTTP requests can lead to a reboot. An attacker can send multiple network packets to trigger this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 3.9 | Impact: 4.0

Affected Packages2 packages

CVEListV5tenda/ac6_v5.0V02.03.01.110
NVDtenda/ac6_firmware02.03.01.110

🔴Vulnerability Details

2
CVEList
CVE-2025-30256: A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V52025-08-20
GHSA
GHSA-mxm9-vq8j-x8j2: A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V52025-08-20