CVE-2025-60341

7.5

Tenda · AC6 V2.0

Tenda AC6 V2.0 firmware version 15.03.06.50 contains a stack overflow vulnerability in the ssid parameter, allowing remote unauthenticated attackers to cause a denial of service.

Executive summary

A stack overflow vulnerability in Tenda AC6 V2.0 routers allows unauthenticated remote attackers to crash the device, resulting in a denial of service.

Vulnerability

The device is susceptible to a stack overflow within the fast_setting_wifi_set function when processing the ssid parameter. This flaw permits an unauthenticated attacker to trigger a system crash via a specially crafted input.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity risk due to the ease of exploitation. A successful attack results in a denial of service, which can disrupt network availability and business operations for users relying on the affected hardware.

Remediation

Immediate Action: Contact Tenda support or check the official vendor portal for firmware updates addressing this stack overflow, as no official patch version is currently identified.

Proactive Monitoring: Monitor device uptime logs and system stability metrics to identify unexpected reboots or service interruptions that may indicate exploitation attempts.

Compensating Controls: Restrict access to the router's management interface to trusted internal IP addresses and disable remote management features to mitigate the risk of unauthenticated access.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept is documented in the technical write-up provided in the references.

Analyst recommendation

Given the high CVSS score and the potential for remote disruption, this vulnerability poses a significant risk to network stability. Administrators should prioritize restricting access to the affected hardware immediately and monitor for vendor-provided firmware updates to permanently remediate the stack overflow condition.

More Tenda CVEs

Sources