VYPR

Ac6 Firmware

by Tenda

CVEs (176)

  • CVE-2023-26976HigApr 4, 2023
    risk 0.50cvss 7.5epss 0.16

    Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

  • CVE-2025-70252HigMar 2, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow…

  • CVE-2025-60343HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the wanMTU, wanSpeed, cloneType, mac, serviceName, serverName, wanMTU2, wanSpeed2, cloneType2, mac2,…

  • CVE-2025-60342HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-60341HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-60340HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the limitSpeed, deviceId, and limitSpeedUp parameters.

  • CVE-2025-60339HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the schedStartTime and schedEndTime parameters.

  • CVE-2025-60337HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-60338HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-55498HigAug 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function.

  • CVE-2025-55482HigAug 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function.

  • CVE-2025-55483HigAug 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters macFilterType and deviceList.

  • CVE-2025-24496HigAug 20, 2025
    risk 0.49cvss 7.5epss 0.00

    An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.110. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets to trigger this vulnerability.

  • CVE-2025-50262HigJul 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the list parameter.

  • CVE-2025-50260HigJul 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via the firewallEn parameter.

  • CVE-2025-46035HigJun 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTime and schedEndTime parameters in an unauthenticated HTTP GET request to the /goform/openSchedWifi endpoint

  • CVE-2025-29121HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file form_fast_setting_wifi_set. Using the timeZone parameter causes a stack-based buffer overflow.

  • CVE-2022-45661HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the setSmartPowerManagement function.

  • CVE-2022-45660HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the schedStartTime parameter in the setSchedWifi function.

  • CVE-2022-45659HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function.

Page 6 of 9