CVE-2025-30256

8.6

Tenda · AC6 V5

A denial of service vulnerability in the Tenda AC6 V5 HTTP header parsing allows unauthenticated attackers to trigger a device reboot via crafted network packets.

Executive summary

A critical denial of service vulnerability in Tenda AC6 V5 hardware allows unauthenticated attackers to force device reboots through malicious HTTP requests.

Vulnerability

This vulnerability, classified as CWE-772 (Missing Release of Resource after Effective Lifetime), occurs within the HTTP header parsing functionality. An unauthenticated remote attacker can send a sequence of crafted network packets to exhaust resources, leading to an involuntary device reboot.

Business impact

The ability for an unauthenticated attacker to remotely trigger a device reboot poses a significant risk to network availability and operational continuity. Given the CVSS score of 8.6, this flaw is categorized as High severity, as it allows for trivial disruption of services without requiring specialized access or user interaction. Frequent reboots may lead to extended downtime for connected clients and potential loss of unsaved configuration data.

Remediation

Immediate Action: Consult the Tenda support portal for the latest firmware release or security advisory to identify a patched version, as no specific fix version is currently identified.

Proactive Monitoring: Monitor network traffic for anomalous or high-frequency HTTP requests directed toward the management interface of the Tenda device.

Compensating Controls: Restrict access to the device management interface to trusted internal IP addresses only, and implement rate limiting on the network perimeter to mitigate the impact of malicious packet floods.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant availability risk to Tenda AC6 V5 users. Organizations should prioritize isolating these devices from public-facing networks until a vendor-supplied patch is installed. Administrators must verify firmware status regularly and apply updates as soon as they become available to eliminate the underlying resource management flaw.

More Tenda CVEs

Sources

Originally found and disclosed by Discovered by Lilith &gt, _&gt, of Cisco Talos., per the CVE Program record.