CVE-2025-60340
7.5Tenda · AC6
Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allow unauthenticated attackers to trigger a Denial of Service via crafted parameter payloads.
Executive summary
A critical vulnerability in the Tenda AC6 router allows unauthenticated remote attackers to crash the device through buffer overflow attacks.
Vulnerability
This vulnerability consists of multiple buffer overflows within the SetClientState function. An unauthenticated attacker can trigger these overflows by injecting malicious payloads into the limitSpeed, deviceId, and limitSpeedUp parameters, resulting in a system denial of service.
Business impact
The exploitation of this vulnerability results in a complete denial of service for the affected networking hardware. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to operational continuity, as compromised routers can be taken offline remotely by attackers, leading to network downtime and potential service disruption for connected business systems.
Remediation
Immediate Action: Contact Tenda support or monitor the official product security page for a firmware update that addresses the buffer overflow in the SetClientState function.
Proactive Monitoring: Review system logs for unusual traffic patterns or malformed requests directed at the administrative interface of the router.
Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only, and implement network segmentation to prevent external actors from reaching the affected service.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical write-up referenced in the CVE record.
Analyst recommendation
Due to the high severity and the presence of a public proof-of-concept, users should treat this vulnerability with urgency. If a firmware update is not currently available, administrators must isolate the affected devices from the public internet to prevent potential remote exploitation until a vendor-supplied patch is applied.