CVE-2025-24322
8.1Tenda · AC6 V5
A critical authentication flaw in Tenda AC6 V5.0 allows unauthenticated attackers to trigger arbitrary code execution via crafted network requests.
Executive summary
A critical vulnerability in the Tenda AC6 V5.0 router allows unauthenticated attackers to execute arbitrary code, posing a severe risk to network integrity.
Vulnerability
This vulnerability is caused by a missing critical step in the authentication process (CWE-304), specifically within the Initial Setup Authentication functionality. An unauthenticated attacker can reach the vulnerable endpoint over the network to trigger arbitrary code execution on the device.
Business impact
The vulnerability carries a CVSS score of 8.1, reflecting a high risk of total system compromise. Successful exploitation allows unauthorized parties to gain full control over the networking hardware, which can be leveraged to intercept traffic, pivot into internal networks, or disrupt critical business communication services.
Remediation
Immediate Action: Contact the vendor or check the official Tenda support portal for firmware updates addressing this flaw, as no specific patch version is currently identified.
Proactive Monitoring: Monitor network traffic for unusual HTTP requests targeting the device administrative interface and review device logs for signs of unauthorized configuration changes.
Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only, or disable remote management features entirely to prevent external exposure.
Exploitation status
Public Exploit Available: No confirmed public exploit exists in the available data.
Analyst recommendation
Given the potential for arbitrary code execution and the high severity of this vulnerability, administrators should prioritize isolating affected Tenda AC6 V5 devices from the public internet. Immediate action is required to verify the availability of vendor-supplied firmware updates and to implement strict network access controls to mitigate the risk of remote exploitation.
More Tenda CVEs
Sources
Originally found and disclosed by Discovered by Lilith >, _>, of Cisco Talos., per the CVE Program record.