Skip to main content

Vendor/product archive

tenda / ac6 CVEs

Beta · best-effort

112 CVEs tagged to tenda / ac643 Critical, 53 High, 13 Medium, 3 Low, 0 Unrated.

CVE-2026-8265

Published May 11, 2026

A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The…

CVSS 2.0 · Low
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-8264

Published May 11, 2026

A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Execu…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-8259

Published May 11, 2026

A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the…

CVSS 2.0 · Low
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-52221

Published Apr 8, 2026

Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-4961

Published Mar 27, 2026

A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request…

CVSS 7.4 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-4960

Published Mar 27, 2026

A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler. Executin…

CVSS 7.4 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-70252

Published Mar 2, 2026

An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be splice…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-12225

Published Oct 27, 2025

A vulnerability has been found in Tenda AC6 15.03.06.50. This issue affects some unknown processing of the file /goform/WifiGuestSet of the component HTTP Request Handler. Such ma…

CVSS 7.4 · High
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-60343

Published Oct 22, 2025

Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the w…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60342

Published Oct 22, 2025

Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability allows attackers to cause a Denial of Se…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60341

Published Oct 22, 2025

Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set function. This vulnerability allows attackers to cause a D…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60340

Published Oct 22, 2025

Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the li…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60339

Published Oct 22, 2025

Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted paylo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60337

Published Oct 22, 2025

Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan function. This vulnerability allows attackers to cause a Denia…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60338

Published Oct 22, 2025

Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient function. This vulnerability allows attackers to cause a Denial o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-57296

Published Sep 19, 2025

Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which processes requests to the /goform/SetIPTVCfg web interface. Whe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57528

Published Sep 19, 2025

An issue was discovered in Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01 allowing attackers to cause a denial of service via the funcname, funcpara1, funcpara2 parameters to the…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55499

Published Aug 20, 2025

Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55483

Published Aug 20, 2025

Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters macFilterType and deviceList.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32010

Published Aug 20, 2025

A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP response can lead to arbitrary code exe…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-31355

Published Aug 20, 2025

A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted malicious file can lead to arbitrary…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 112 CVEsPage 1 of 5