CVE-2025-50262Classic Buffer Overflow in AC6 Firmware

Severity
7.5HIGHNVD
EPSS
0.1%
top 67.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 3

Description

Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the list parameter.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDtenda/ac6_firmware15.03.05.16_multi

🔴Vulnerability Details

2
CVEList
CVE-2025-50262: Tenda AC6 v152025-07-03
GHSA
GHSA-73r8-cfhc-ffw6: Tenda AC6 v152025-07-03

📋Vendor Advisories

1
Microsoft
bpf: Fix out-of-bounds write in trie_get_next_key()2024-11-12
CVE-2025-50262 — Classic Buffer Overflow in Tenda | cvebase