CVE-2025-70252
7.5Tenda · AC6V2
A stack-based buffer overflow in the Tenda AC6V2 router allows unauthenticated attackers to cause a denial of service via the /goform/WifiWpsStart endpoint.
Executive summary
A critical stack overflow vulnerability in Tenda AC6V2 routers permits unauthenticated remote attackers to crash the device, leading to a complete denial of service.
Vulnerability
The vulnerability exists in the /goform/WifiWpsStart function, which fails to perform adequate size checks when processing the index and mode parameters. This allows an unauthenticated attacker to inject malicious data that results in a stack overflow.
Business impact
The exploitation of this vulnerability results in a denial of service, which can render critical networking infrastructure non-functional. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to business continuity by enabling attackers to disrupt network availability remotely without requiring authentication.
Remediation
Immediate Action: Contact Tenda support to inquire about firmware updates for the AC6V2 series, as no official patch is currently identified in the provided data.
Proactive Monitoring: Monitor network traffic for unusual GET or POST requests directed at the /goform/WifiWpsStart endpoint, which may indicate attempted exploitation.
Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only, and implement a firewall rule to block external access to the /goform/ directory.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept is available via the linked researcher repository.
Analyst recommendation
Due to the lack of an official patch and the presence of a public proof-of-concept, this vulnerability must be treated with high urgency. Administrators should prioritize restricting network access to the affected devices to prevent unauthorized remote exploitation while awaiting further guidance or a firmware release from Tenda.