Information Disclosure Vulnerability in Tenda AC6 Router
CVE-2025-24496

7.5HIGH

Key Information:

Vendor

Tenda

Status
Vendor
CVE Published:
20 August 2025

What is CVE-2025-24496?

An information disclosure vulnerability has been identified in the /goform/getproductInfo functionality of the Tenda AC6 router. This vulnerability allows attackers to send specially crafted packets that may lead to the exposure of sensitive information. It is essential for users to implement necessary security measures to protect their devices from potential exploitation.

Affected Version(s)

AC6 V5.0 V02.03.01.110

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Lilith >_> of Cisco Talos.
.
CVE-2025-24496 : Information Disclosure Vulnerability in Tenda AC6 Router