Buffer Overflow Vulnerability in Tenda AC6 Router by Tenda
CVE-2025-52221

7.5HIGH

Key Information:

Vendor

Tenda

Vendor
CVE Published:
8 April 2026

What is CVE-2025-52221?

The Tenda AC6 router version 15.03.05.16_multi has a buffer overflow vulnerability in the formSetCfm function. Exploited through the funcname, funcpara1, and funcpara2 parameters, this vulnerability could allow attackers to execute arbitrary code or manipulate the device's functionality, posing significant risks to users' networks and data integrity.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.