CVE-2025-55503
7.3Tenda · AC6
A stack overflow vulnerability exists in Tenda AC6 V15.03.06.23 via the deviceName parameter in the saveParentControlInfo function, allowing potential remote code execution.
Executive summary
A stack overflow vulnerability in Tenda AC6 routers poses a significant risk of remote exploitation, potentially allowing unauthenticated attackers to compromise device integrity.
Vulnerability
This is a stack-based buffer overflow vulnerability triggered by sending a crafted payload to the deviceName parameter within the saveParentControlInfo function. The vulnerability is exploitable by an unauthenticated attacker over the network.
Business impact
Successful exploitation of this flaw allows an attacker to execute arbitrary code on the affected router. This could lead to a total loss of network confidentiality and integrity, potentially enabling man-in-the-middle attacks, unauthorized access to internal network resources, or the use of the device as a botnet node. With a CVSS score of 7.3, this represents a high-severity risk to operational stability and network security.
Remediation
Immediate Action: Since a vendor-supplied patch is currently unknown, users should restrict administrative access to the device management interface and disable remote management features.
Proactive Monitoring: Monitor network traffic for unusual patterns or payloads directed at router management interfaces, and review device logs for signs of unauthorized configuration changes.
Compensating Controls: Implement network segmentation to isolate the router from critical internal assets and utilize a firewall to block unauthorized access to the device management ports.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the research write-up provided in the CVE references.
Analyst recommendation
Given the availability of a public proof-of-concept and the nature of stack-based buffer overflows, this vulnerability presents a credible threat to network infrastructure. Administrators must prioritize isolating vulnerable Tenda AC6 devices from the public internet and closely monitor for any vendor-issued firmware updates to address this flaw permanently.