Buffer Overflow Exploit in Tenda AC6 Router Firmware
CVE-2025-60340
7.5HIGH
What is CVE-2025-60340?
Multiple buffer overflow vulnerabilities have been identified in the SetClientState function of the Tenda AC6 router firmware version 15.03.06.50. By manipulating parameters such as limitSpeed, deviceId, and limitSpeedUp, attackers can inject specially crafted payloads, enabling them to execute a denial of service attack. This allows malicious actors to disrupt normal operations, leading to potential downtime and degraded performance for users relying on the affected devices.