CVE-2025-55482

7.5

Tenda · AC6

A buffer overflow vulnerability in the formSetCfm function of the Tenda AC6 router allows for potential denial of service attacks.

Executive summary

The Tenda AC6 router is susceptible to a buffer overflow vulnerability that could lead to a denial of service condition if exploited by an unauthenticated attacker.

Vulnerability

This vulnerability is a buffer overflow flaw located in the formSetCfm function. It is reachable by an unauthenticated attacker, as indicated by the network attack vector and no requirement for user interaction or privileges.

Business impact

Successful exploitation of this vulnerability results in a denial of service, which can render the affected networking hardware unresponsive. Given the CVSS score of 7.5, this high severity flaw poses a significant operational risk, as it could disrupt critical network connectivity and business communications.

Remediation

Immediate Action: Since a specific patch is not currently identified, users should restrict administrative access to the device to trusted management interfaces only.

Proactive Monitoring: Monitor network traffic for unusual spikes or malformed requests directed at the router management interface.

Compensating Controls: Implement firewall rules to block external access to the device management interface, ensuring it is only accessible from an internal, trusted network segment.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists and is attributed to the vulnerability research published on GitHub.

Analyst recommendation

Given the high severity of this buffer overflow, network administrators should prioritize securing Tenda AC6 devices by isolating them from public-facing network segments. We strongly recommend monitoring vendor communication channels for forthcoming firmware updates that address this flaw, as patching remains the only definitive method to eliminate this risk.

More Tenda CVEs

Sources