VendorsTendaac6all versions
Vulnerabilities

Tenda AC6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

112CVEs
CVE-2022-41482
Tenda AC1200 US_AC6V2.0RTL_V15.03.06.51_multi_TDE01 was discovered to contain a buffer overflow in the 0x47c5dc function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2022-10-13 · Modified
7.5EPSS 0.008
CVE-2025-46035
Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTime and schedEndTime parameters in an unauthenticated HTTP GET request to the /goform/openSchedWifi endpoint
Published 2025-06-12 · Modified
7.5EPSS 0.006
CVE-2025-60338
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Modified
7.5EPSS 0.005
CVE-2025-29121
A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file form_fast_setting_wifi_set. Using the timeZone parameter causes a stack-based buffer overflow.
Published 2025-03-20 · Analyzed
7.5EPSS 0.005
CVE-2025-70252
An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow vulnerability.
Published 2026-03-02 · Analyzed
7.5EPSS 0.004
CVE-2025-60342
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Modified
7.5EPSS 0.004
CVE-2025-50260
Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via the firewallEn parameter.
Published 2025-07-03 · Analyzed
7.5EPSS 0.004
CVE-2025-50262
Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the list parameter.
Published 2025-07-03 · Analyzed
7.5EPSS 0.004
CVE-2025-60337
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Modified
7.5EPSS 0.004
CVE-2025-60343
Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the wanMTU, wanSpeed, cloneType, mac, serviceName, serverName, wanMTU2, wanSpeed2, cloneType2, mac2, serviceName2, and serverName2 parameters.
Published 2025-10-22 · Analyzed
7.5EPSS 0.004
CVE-2025-60340
Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the limitSpeed, deviceId, and limitSpeedUp parameters.
Published 2025-10-22 · Modified
7.5EPSS 0.004
CVE-2025-60339
Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the schedStartTime and schedEndTime parameters.
Published 2025-10-22 · Modified
7.5EPSS 0.004
CVE-2025-60341
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Modified
7.5EPSS 0.004
CVE-2025-55483
Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters macFilterType and deviceList.
Published 2025-08-20 · Analyzed
7.5EPSS 0.004
CVE-2025-55498
Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function.
Published 2025-08-20 · Analyzed
7.5EPSS 0.004
CVE-2025-55482
Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function.
Published 2025-08-20 · Analyzed
7.5EPSS 0.004
CVE-2025-24496
An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.110. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets to trigger this vulnerability.
Published 2025-08-20 · Modified
7.5EPSS 0.004
CVE-2025-50528
A buffer overflow vulnerability exists in the fromNatStaticSetting function of Tenda AC6 <=V15.03.05.19 via the page parameter.
Published 2025-06-27 · Analyzed
7.3EPSS 0.004
CVE-2025-55503
Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.
Published 2025-08-20 · Analyzed
7.3EPSS 0.003
CVE-2026-8265
Tenda AC6 httpd getLogFile get_log_file os command injection
Published 2026-05-11 · Analyzed
7.2EPSS 0.083
CVE-2026-8259
Tenda AC6 httpd telnet os command injection
Published 2026-05-11 · Analyzed
7.2EPSS 0.083
CVE-2025-57296
Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which processes requests to the /goform/SetIPTVCfg web interface. When handling the list and vlanId parameters, the sub_ADBC0 helper function concatenates these user-supplied values into nvram set system commands using doSystemCmd, without validating or sanitizing special characters (e.g., ;, ", #). An unauthenticated or authenticated attacker can exploit this by submitting a crafted POST request, leading to arbitrary system command execution on the affected device.
Published 2025-09-19 · Analyzed
6.5EPSS 0.033
CVE-2025-25507
There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command execution.
Published 2025-02-21 · Analyzed
6.5EPSS 0.005
CVE-2025-50641
Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the addWifiMacFilter function via the parameter deviceId.
Published 2025-07-01 · Modified
6.5EPSS 0.004
CVE-2022-45674
Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
Published 2022-12-02 · Modified
6.5EPSS 0.003
CVE-2022-45673
Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.
Published 2022-12-02 · Modified
6.5EPSS 0.003
CVE-2025-25505
Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.
Published 2025-02-21 · Analyzed
6.5EPSS 0.003
CVE-2025-44172
Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.
Published 2025-06-02 · Analyzed
6.5EPSS 0.003
CVE-2025-55499
Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function.
Published 2025-08-20 · Analyzed
6.5EPSS 0.003
CVE-2025-55495
Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.
Published 2025-08-27 · Analyzed
6.5EPSS 0.002
CVE-2022-40010
Tenda AC6 AC1200 Smart Dual-Band WiFi Router 15.03.06.50_multi was discovered to contain a cross-site scripting (XSS) vulnerability via the deviceId parameter in the Parental Control module.
Published 2023-06-26 · Modified
5.4EPSS 0.005
CVE-2021-40546
Tenda AC6 US_AC6V4.0RTL_V02.03.01.26_cn.bin allows attackers (who have the administrator password) to cause a denial of service (device crash) via a long string in the wifiPwd_5G parameter to /goform/setWifi.
Published 2023-09-05 · Modified
4.9EPSS 0.007
← Prev3 / 3