CVE-2025-32010
8.1Tenda · AC6 V5
A stack-based buffer overflow in the Tenda AC6 V5 Cloud API allows unauthenticated remote attackers to achieve arbitrary code execution via a crafted HTTP response.
Executive summary
A critical stack-based buffer overflow vulnerability in Tenda AC6 V5 routers poses a severe risk of remote code execution.
Vulnerability
This vulnerability is a stack-based buffer overflow (CWE-121) located in the Cloud API functionality. An unauthenticated remote attacker can trigger the flaw by sending a specially crafted HTTP response to the target device.
Business impact
The ability for an unauthenticated attacker to execute arbitrary code on a network device represents a total compromise of the affected hardware. This could lead to full network interception, unauthorized access to internal resources, and the potential for the device to be used as a pivot point for further lateral movement within the business environment. The CVSS score of 8.1 reflects the high severity of this remote exploitability.
Remediation
Immediate Action: Consult the Tenda support portal and Talos vulnerability report TALOS-2025-2168 to verify if a firmware update has been released for your specific hardware revision.
Proactive Monitoring: Monitor network traffic for anomalous HTTP requests directed at the Cloud API endpoints of your Tenda devices.
Compensating Controls: Restrict access to the router management interface and Cloud API functionality to trusted IP addresses only, and employ a network firewall to filter potentially malicious inbound HTTP traffic.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability poses a significant risk to organizational perimeter security. IT administrators should prioritize the identification of all affected Tenda AC6 V5 units and apply vendor-provided firmware updates as soon as they become available. Until a patch is confirmed, network segmentation should be utilized to isolate these devices from critical business segments.
More Tenda CVEs
Sources
Originally found and disclosed by Discovered by Lilith >, _>, of Cisco Talos., per the CVE Program record.