VendorsTendaac6_firmware15.03.06.50
Vulnerabilities

Tenda ac6 Firmware 15.03.06.50

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2025-12225
Tenda AC6 HTTP Request WifiGuestSet stack-based overflow
Published 2025-10-27 · Analyzed
9.0EPSS 0.009
CVE-2025-7914
Tenda AC6 httpd setparentcontrolinfo buffer overflow
Published 2025-07-21 · Analyzed
9.0EPSS 0.009
CVE-2024-51116
Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'.
Published 2024-11-05 · Analyzed
8.8EPSS 0.004
CVE-2024-46450
Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication via a crafted web request.
Published 2025-01-16 · Analyzed
8.1EPSS 0.004
CVE-2025-60338
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Modified
7.5EPSS 0.005
CVE-2025-60342
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Modified
7.5EPSS 0.004
CVE-2025-60337
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Modified
7.5EPSS 0.004
CVE-2025-60339
Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the schedStartTime and schedEndTime parameters.
Published 2025-10-22 · Modified
7.5EPSS 0.004
CVE-2025-60340
Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the limitSpeed, deviceId, and limitSpeedUp parameters.
Published 2025-10-22 · Modified
7.5EPSS 0.004
CVE-2025-60343
Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the wanMTU, wanSpeed, cloneType, mac, serviceName, serverName, wanMTU2, wanSpeed2, cloneType2, mac2, serviceName2, and serverName2 parameters.
Published 2025-10-22 · Analyzed
7.5EPSS 0.004
CVE-2025-60341
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Modified
7.5EPSS 0.004