CVE-2025-55498

7.5

Tenda · AC6

A buffer overflow vulnerability exists in the Tenda AC6 router, which allows an unauthenticated attacker to trigger a denial of service via the time parameter in the fromSetSysTime function.

Executive summary

A buffer overflow vulnerability in Tenda AC6 routers poses a significant risk of service disruption due to the potential for unauthenticated denial of service attacks.

Vulnerability

This is a buffer overflow vulnerability residing in the fromSetSysTime function. An unauthenticated attacker can supply a malicious input to the time parameter to crash the device.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation results in a denial of service, which can cause significant operational downtime for organizations relying on these devices for network connectivity.

Remediation

Immediate Action: Since a patch is currently unknown, administrators should isolate affected devices from the public internet and restrict management access to trusted internal networks only.

Proactive Monitoring: Monitor network logs for unusual traffic patterns directed toward the device management interface or repeated attempts to modify system time settings.

Compensating Controls: Deploy a Web Application Firewall or network intrusion detection system to filter malformed requests targeting the system time configuration parameters.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the research write-up provided in the references.

Analyst recommendation

Given the presence of a public proof-of-concept and the high severity of the potential denial of service, Tenda AC6 users must prioritize network segmentation. Until the vendor releases a firmware update to resolve the buffer overflow, ensure that the device management interface is not exposed to the internet to prevent unauthorized access.

More Tenda CVEs

Sources