CVE-2025-31355

7.2

Tenda · AC6 V5

A firmware signature validation vulnerability in Tenda AC6 V5 allows an authenticated attacker to achieve arbitrary code execution via a specially crafted file.

Executive summary

A critical firmware vulnerability in Tenda AC6 V5 devices permits arbitrary code execution, posing a severe risk to device integrity and network security.

Vulnerability

This vulnerability, categorized as CWE-494, stems from a failure to perform adequate integrity checks during firmware updates. The flaw allows an attacker with administrative privileges to upload a malicious file, which the system then executes, resulting in full system compromise.

Business impact

The ability to execute arbitrary code on networking hardware provides an attacker with complete control over the device, effectively granting them a foothold within the local network. With a CVSS score of 7.2, this vulnerability represents a high risk, as it can lead to unauthorized data interception, lateral movement, and persistent access to critical infrastructure.

Remediation

Immediate Action: Contact Tenda support or monitor the official vendor portal for a firmware update that addresses this signature validation flaw, as no patch is currently confirmed.

Proactive Monitoring: Review administrative access logs for unauthorized firmware update attempts and monitor network traffic for unusual outbound connections originating from the router.

Compensating Controls: Restrict administrative access to the router interface to trusted management IP addresses only and disable remote management features to reduce the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Given the potential for total system compromise, administrators should treat this vulnerability with high urgency. Ensure that administrative interfaces are not exposed to the public internet and verify that all Tenda AC6 V5 devices are isolated from untrusted segments until a vendor-supplied firmware patch is applied.

More Tenda CVEs

Sources

Originally found and disclosed by Discovered by Lilith &gt, _&gt, of Cisco Talos., per the CVE Program record.