Tenda
Tenda AC6 Firmware: vulnerabilidades y CVE
Tenda AC6 Firmware tiene 108 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 47 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE108
Últimos 12 meses15
Críticas47
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-8265 | Baja (2) | 8.3% | — | 11 may 2026 | A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag… |
| CVE-2026-8264 | Baja (2.1) | 6.5% | — | 11 may 2026 | A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument… |
| CVE-2026-8259 | Baja (2) | 8.3% | — | 11 may 2026 | A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command… |
| CVE-2025-52221 | Crítica (9.8) | 0.39% | — | 8 abr 2026 | Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters. |
| CVE-2026-4961 | Alta (7.4) | 1.0% | — | 27 mar 2026 | A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. The manipulation of the… |
| CVE-2026-4960 | Alta (7.4) | 1.0% | — | 27 mar 2026 | A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of the argument… |
| CVE-2025-70252 | Alta (7.5) | 0.46% | — | 2 mar 2026 | An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that… |
| CVE-2025-12225 | Alta (7.4) | 1.0% | — | 27 oct 2025 | A vulnerability has been found in Tenda AC6 15.03.06.50. This issue affects some unknown processing of the file /goform/WifiGuestSet of the component HTTP Request Handler. Such manipulation of the argument shareSpeed… |
| CVE-2025-60343 | Alta (7.5) | 0.41% | — | 22 oct 2025 | Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the wanMTU, wanSpeed, cloneType, mac,… |
| CVE-2025-60342 | Alta (7.5) | 0.42% | — | 22 oct 2025 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. |
| CVE-2025-60341 | Alta (7.5) | 0.40% | — | 22 oct 2025 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2025-60340 | Alta (7.5) | 0.41% | — | 22 oct 2025 | Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the limitSpeed, deviceId, and limitSpeedUp… |
| CVE-2025-60339 | Alta (7.5) | 0.41% | — | 22 oct 2025 | Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the schedStartTime and… |
| CVE-2025-60337 | Alta (7.5) | 0.41% | — | 22 oct 2025 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. |
| CVE-2025-60338 | Alta (7.5) | 0.49% | — | 22 oct 2025 | Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. |
| CVE-2025-57296 | Media (6.5) | 3.3% | — | 19 sept 2025 | Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which processes requests to the /goform/SetIPTVCfg web interface. When handling the list and vlanId… |
| CVE-2025-57528 | Alta (7.7) | 0.44% | — | 19 sept 2025 | An issue was discovered in Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01 allowing attackers to cause a denial of service via the funcname, funcpara1, funcpara2 parameters to the formSetCfm function (uri path: SetCfm). |
| CVE-2025-55495 | Media (6.5) | 0.25% | — | 27 ago 2025 | Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function. |
| CVE-2025-55498 | Alta (7.5) | 0.40% | — | 20 ago 2025 | Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function. |
| CVE-2025-55482 | Alta (7.5) | 0.40% | — | 20 ago 2025 | Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function. |
| CVE-2025-55503 | Alta (7.3) | 0.28% | — | 20 ago 2025 | Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function. |
| CVE-2025-55499 | Media (6.5) | 0.26% | — | 20 ago 2025 | Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function. |
| CVE-2025-55483 | Alta (7.5) | 0.40% | — | 20 ago 2025 | Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters macFilterType and deviceList. |
| CVE-2025-32010 | Crítica (9.8) | 0.69% | — | 20 ago 2025 | A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP response can lead to arbitrary code execution. An attacker can send an HTTP… |
| CVE-2025-31355 | Crítica (9.8) | 0.30% | — | 20 ago 2025 | A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted malicious file can lead to arbitrary code execution. An attacker can provide… |
| CVE-2025-30256 | Alta (7.5) | 0.39% | — | 20 ago 2025 | A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted series of HTTP requests can lead to a reboot. An attacker can send multiple network… |
| CVE-2025-27129 | Crítica (9.8) | 2.1% | — | 20 ago 2025 | An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send packets… |
| CVE-2025-24496 | Alta (7.5) | 0.37% | — | 20 ago 2025 | An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.110. Specially crafted network packets can lead to a disclosure of sensitive information. An… |
| CVE-2025-24322 | Crítica (9.8) | 0.57% | — | 20 ago 2025 | An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted network request can lead to arbitrary code execution. An… |
| CVE-2025-7914 | Alta (8.7) | 0.87% | — | 21 jul 2025 | A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is the function setparentcontrolinfo of the component httpd. The manipulation leads to buffer overflow.… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.