CVE-2025-55483

7.5

Tenda · AC6

The Tenda AC6 V15.03.06.23 router is vulnerable to a buffer overflow in the formSetMacFilterCfg function, which can be triggered via malicious input in the macFilterType and deviceList parameters.

Executive summary

A buffer overflow vulnerability in the Tenda AC6 router allows unauthenticated attackers to cause a denial of service condition through specially crafted network requests.

Vulnerability

This flaw is a buffer overflow occurring within the formSetMacFilterCfg function. It can be triggered by an unauthenticated attacker by sending malformed data to the macFilterType or deviceList parameters.

Business impact

The successful exploitation of this buffer overflow results in a denial of service, rendering the affected networking hardware unresponsive. Given the CVSS score of 7.5, this high severity vulnerability poses a significant risk to operational continuity, as an attacker can remotely disrupt network traffic and connectivity without requiring any prior authentication.

Remediation

Immediate Action: As no official patch is currently available, users should restrict administrative access to the device management interface to trusted internal networks only.

Proactive Monitoring: Security teams should monitor device logs for unexpected crashes or service restarts and inspect network traffic for unusually long or malformed parameter strings targeting the MAC filter configuration interface.

Compensating Controls: Deploy a network firewall or Web Application Firewall (WAF) to filter and block suspicious traffic directed at the router's web management interface.

Exploitation status

Public Exploit Available: Yes, a proof of concept exists, as documented in the technical write up referenced in the CVE record.

Analyst recommendation

The vulnerability presents a high risk to availability due to the ease of triggering a denial of service from an unauthenticated state. Network administrators must isolate affected Tenda AC6 devices from the public internet immediately and monitor for vendor releases to apply the official patch as soon as it becomes available.

More Tenda CVEs

Sources