CVE-2025-60341
7.5Tenda · AC6 V2.0
Tenda AC6 V2.0 firmware version 15.03.06.50 contains a stack overflow vulnerability in the ssid parameter, allowing remote unauthenticated attackers to cause a denial of service.
Executive summary
A stack overflow vulnerability in Tenda AC6 V2.0 routers allows unauthenticated remote attackers to crash the device, resulting in a denial of service.
Vulnerability
The device is susceptible to a stack overflow within the fast_setting_wifi_set function when processing the ssid parameter. This flaw permits an unauthenticated attacker to trigger a system crash via a specially crafted input.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk due to the ease of exploitation. A successful attack results in a denial of service, which can disrupt network availability and business operations for users relying on the affected hardware.
Remediation
Immediate Action: Contact Tenda support or check the official vendor portal for firmware updates addressing this stack overflow, as no official patch version is currently identified.
Proactive Monitoring: Monitor device uptime logs and system stability metrics to identify unexpected reboots or service interruptions that may indicate exploitation attempts.
Compensating Controls: Restrict access to the router's management interface to trusted internal IP addresses and disable remote management features to mitigate the risk of unauthenticated access.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept is documented in the technical write-up provided in the references.
Analyst recommendation
Given the high CVSS score and the potential for remote disruption, this vulnerability poses a significant risk to network stability. Administrators should prioritize restricting access to the affected hardware immediately and monitor for vendor-provided firmware updates to permanently remediate the stack overflow condition.