CVE-2025-60338
7.5Tenda · AC6 V2
A stack overflow vulnerability exists in the Tenda AC6 V2 router within the DhcpListClient function, allowing unauthenticated attackers to trigger a denial of service via crafted input.
Executive summary
The Tenda AC6 V2 router contains a stack overflow vulnerability that allows unauthenticated remote attackers to cause a denial of service on affected devices.
Vulnerability
This is a stack-based buffer overflow vulnerability triggered within the DhcpListClient function when processing the page parameter. The vulnerability is exploitable by unauthenticated attackers over the network.
Business impact
Successful exploitation of this vulnerability results in a denial of service, effectively taking the router offline and disrupting network connectivity for all downstream clients. With a CVSS score of 7.5, this high severity flaw poses a significant risk to operational continuity, as an attacker can repeatedly crash the device and prevent legitimate users from accessing critical network services.
Remediation
Immediate Action: Check the Tenda support portal for firmware updates addressing this stack overflow. If no patch is available, restrict management access to the router to trusted internal networks only.
Proactive Monitoring: Monitor device uptime logs for frequent, unexplained reboots or service interruptions which may indicate exploitation attempts.
Compensating Controls: Deploy a firewall or access control list to block unauthorized access to the router management interface, particularly from untrusted external sources.
Exploitation status
Public Exploit Available: Yes, a proof of concept exists, as documented in the technical write-up referenced by the CVE record.
Analyst recommendation
Given the high severity and the availability of a proof of concept, administrators should treat this vulnerability with urgency. If a firmware update is not currently provided by the vendor, implementing network-level access controls to isolate the router interface is essential to reduce the attack surface until a permanent patch is deployed.