CVE-2025-60342

7.5

Tenda · AC6 V2

A stack overflow vulnerability in the Tenda AC6 V2 router allows unauthenticated remote attackers to trigger a denial of service via a crafted input to the addressNat function.

Executive summary

A stack overflow vulnerability in Tenda AC6 V2 routers enables unauthenticated attackers to cause a denial of service, potentially disrupting network connectivity.

Vulnerability

This is a stack overflow vulnerability occurring within the addressNat function, specifically triggered by the page parameter. The vulnerability is exploitable by unauthenticated remote attackers who can send crafted input to the target device.

Business impact

Successful exploitation of this vulnerability results in a denial of service, which can cause significant operational downtime for users relying on the affected router. With a CVSS score of 7.5, the vulnerability is classified as High, reflecting the ease of exploitation and the potential for complete service disruption in business environments utilizing this hardware.

Remediation

Immediate Action: Contact the vendor for official firmware updates and monitor the support portal for a patch addressing this stack overflow. If no patch is currently available, disconnect the management interface from the public internet.

Proactive Monitoring: Review device logs for unusual traffic patterns or recurring crashes associated with the addressNat function. Monitor for unexpected device reboots or loss of network connectivity.

Compensating Controls: Implement strict firewall rules to restrict access to the device management interface, ensuring it is only accessible from trusted internal management IP addresses.

Exploitation status

Public Exploit Available: Yes, a proof of concept exists, as documented in the research write up linked by the CVE record.

Analyst recommendation

Given the availability of a public proof of concept and the potential for network disruption, administrators should prioritize securing the device management interface. Restrict access to the router to prevent unauthenticated interaction until an official firmware patch is provided by the vendor to remediate this vulnerability.

More Tenda CVEs

Sources