PT-2025-38541 · Tenda · Tenda Ac6

·

CVE-2025-57528

·

Published

2025-05-15

·

Updated

2025-09-19

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Tenda AC6 versions 15.03.05.16
Description An issue exists in Tenda AC6 that allows attackers to cause a denial of service. This is achieved by manipulating the funcname, funcpara1, and funcpara2 parameters within the /SetCfm API endpoint, specifically through the formSetCfm function.
Recommendations Restrict or disable access to the /SetCfm API endpoint. Avoid using the funcname, funcpara1, and funcpara2 parameters in the affected API endpoint until the issue is resolved.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12453
CVE-2025-57528

Affected Products

Tenda Ac6