VYPR
Critical severity9.8NVD Advisory· Published Dec 30, 2025· Updated Jun 17, 2026

CVE-2025-15255

CVE-2025-15255

Description

A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of the component R7websSsecurityHandler. Executing a manipulation of the argument Cookie can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Tenda/W6 S Firmwarev52 versions
    cpe:2.3:o:tenda:w6-s_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:tenda:w6-s_firmware:*:*:*:*:*:*:*:*range: 1.0.0.4(510)
    • cpe:2.3:o:tenda:w6-s_firmware:1.0.0.4\(510\):*:*:*:*:*:*:*
  • Tenda/W6-Sllm-fuzzy
    Range: 1.0.0.4(510)

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.