CVE-2025-60343

7.5

Tenda · AC6

Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allow for remote Denial of Service (DoS) attacks via crafted parameter injection.

Executive summary

A remote buffer overflow vulnerability in Tenda AC6 routers allows unauthenticated attackers to trigger a Denial of Service condition on affected devices.

Vulnerability

The vulnerability exists within the AdvSetMacMtuWan function, where improper bounds checking allows an unauthenticated attacker to inject malicious payloads into multiple configuration parameters, such as wanMTU and mac. This memory corruption flaw leads to a system crash, effectively resulting in a Denial of Service.

Business impact

The exploitation of this vulnerability results in service disruption, which can lead to significant network downtime for organizations or home users relying on the affected hardware. Given the CVSS score of 7.5, this is classified as a High severity issue because it does not require authentication and can be triggered remotely, making the device highly susceptible to disruption.

Remediation

Immediate Action: Contact the vendor support channels to inquire about available firmware updates for the Tenda AC6, as no official patch version is currently documented.

Proactive Monitoring: Monitor device uptime logs and network interface stability to identify unexpected reboots or service interruptions that may indicate an ongoing attack.

Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only, and ensure the device is not directly exposed to the public internet.

Exploitation status

Public Exploit Available: Yes, a public proof of concept exists, as documented in the technical write-up referenced in the CVE record.

Analyst recommendation

Due to the remote and unauthenticated nature of this vulnerability, immediate mitigation is required to prevent potential network service outages. Administrators should prioritize restricting management access to the device and maintain close contact with the vendor for the release of a security-hardened firmware version.

More Tenda CVEs

Sources