Tenda Ac6 Firmware vulnerabilities

104 known vulnerabilities affecting tenda/ac6_firmware.

Total CVEs
104
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL46HIGH46MEDIUM12

Vulnerabilities

Page 2 of 6
CVE-2025-30256HIGHCVSS 7.5v02.03.01.1102025-08-20
CVE-2025-30256 [HIGH] CWE-772 CVE-2025-30256: A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted series of HTTP requests can lead to a reboot. An attacker can send multiple network packets to trigger this vulnerability.
nvd
CVE-2025-55503HIGHCVSS 7.3v15.03.06.23_multi2025-08-20
CVE-2025-55503 [HIGH] CWE-121 CVE-2025-55503: Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.
nvd
CVE-2025-55482HIGHCVSS 7.5v15.03.06.23_multi2025-08-20
CVE-2025-55482 [HIGH] CWE-121 CVE-2025-55482: Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function. Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function.
nvd
CVE-2025-55498HIGHCVSS 7.5v15.03.06.23_multi2025-08-20
CVE-2025-55498 [HIGH] CWE-121 CVE-2025-55498: Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in t Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function.
nvd
CVE-2025-55499MEDIUMCVSS 6.5v15.03.06.232025-08-20
CVE-2025-55499 [MEDIUM] CWE-120 CVE-2025-55499: Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function.
nvd
CVE-2025-7914HIGHCVSS 8.7v15.03.06.502025-07-21
CVE-2025-7914 [HIGH] CWE-119 CVE-2025-7914: A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is the function setparentcontrolinfo of the component httpd. The manipulation leads to buffer overflow. The attack can be launched remotely.
nvd
CVE-2025-50263HIGHCVSS 8.1v15.03.05.16_multi2025-07-03
CVE-2025-50263 [HIGH] CWE-120 CVE-2025-50263: Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the list parameter.
nvd
CVE-2025-50258HIGHCVSS 8.1v15.03.05.16_multi2025-07-03
CVE-2025-50258 [HIGH] CWE-120 CVE-2025-50258: Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the time parameter.
nvd
CVE-2025-50262HIGHCVSS 7.5v15.03.05.16_multi2025-07-03
CVE-2025-50262 [HIGH] CWE-120 CVE-2025-50262: Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the list parameter.
nvd
CVE-2025-50260HIGHCVSS 7.5v15.03.05.16_multi2025-07-03
CVE-2025-50260 [HIGH] CWE-121 CVE-2025-50260: Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via the firewallEn parameter.
nvd
CVE-2025-50641MEDIUMCVSS 6.5v15.03.05.16_multi2025-07-01
CVE-2025-50641 [MEDIUM] CWE-120 CVE-2025-50641: Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the addWifiMacFilter function via th Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the addWifiMacFilter function via the parameter deviceId.
nvd
CVE-2025-50528HIGHCVSS 7.3≤ 15.03.05.192025-06-27
CVE-2025-50528 [HIGH] CWE-121 CVE-2025-50528: A buffer overflow vulnerability exists in the fromNatStaticSetting function of Tenda AC6 <=V15.03.05 A buffer overflow vulnerability exists in the fromNatStaticSetting function of Tenda AC6 <=V15.03.05.19 via the page parameter.
nvd
CVE-2025-46035HIGHCVSS 7.5v15.03.05.162025-06-12
CVE-2025-46035 [HIGH] CWE-120 CVE-2025-46035: Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTime and schedEndTime parameters in an unauthenticated HTTP GET request to the /goform/openSchedWifi endpoint
nvd
CVE-2025-5854HIGHCVSS 7.4v15.03.05.162025-06-09
CVE-2025-5854 [HIGH] CWE-119 CVE-2025-5854: A vulnerability, which was classified as critical, has been found in Tenda AC6 15.03.05.16. Affected A vulnerability, which was classified as critical, has been found in Tenda AC6 15.03.05.16. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-5855HIGHCVSS 7.4v15.03.05.162025-06-09
CVE-2025-5855 [HIGH] CWE-119 CVE-2025-5855: A vulnerability, which was classified as critical, was found in Tenda AC6 15.03.05.16. This affects A vulnerability, which was classified as critical, was found in Tenda AC6 15.03.05.16. This affects the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument rebootTime leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be us
nvd
CVE-2025-5853HIGHCVSS 7.4v15.03.05.162025-06-09
CVE-2025-5853 [HIGH] CWE-119 CVE-2025-5853: A vulnerability classified as critical was found in Tenda AC6 15.03.05.16. Affected by this vulnerab A vulnerability classified as critical was found in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg. The manipulation of the argument remoteIp leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be us
nvd
CVE-2025-5852HIGHCVSS 7.4v15.03.05.162025-06-09
CVE-2025-5852 [HIGH] CWE-119 CVE-2025-5852: A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the func A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function formSetPPTPUserList of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-44172MEDIUMCVSS 6.5v15.03.05.162025-06-02
CVE-2025-44172 [MEDIUM] CWE-121 CVE-2025-44172: Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setS Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.
nvd
CVE-2025-29121HIGHCVSS 7.5v15.03.05.162025-03-20
CVE-2025-29121 [HIGH] CWE-121 CVE-2025-29121: A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file form_fast_setting_wifi_set. Using the timeZone parameter causes a stack-based buffer overflow.
nvd
CVE-2025-29029CRITICALCVSS 9.8v15.03.05.162025-03-14
CVE-2025-29029 [CRITICAL] CWE-787 CVE-2025-29029: Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function. Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.
nvd