Stack-based Buffer Overflow in Tenda AC6 Router by Tenda
CVE-2025-32010

8.1HIGH

Key Information:

Vendor

Tenda

Status
Vendor
CVE Published:
20 August 2025

What is CVE-2025-32010?

A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 routers. By sending a specially crafted HTTP response, an attacker can exploit this flaw to execute arbitrary code on the device. This vulnerability poses significant risks for users, potentially allowing unauthorized access and control over affected devices.

Affected Version(s)

AC6 V5.0 V02.03.01.110

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Lilith >_> of Cisco Talos.
.