📦 Ac6 Firmware

by Tenda

🔍 What is Ac6 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-27129

CRITICAL CVSS 9.8 Aug 20, 2025

An authentication bypass vulnerability in Tenda AC6 routers allows attackers to bypass HTTP authentication and execute arbitrary code. This affects Tenda AC6 V5.0 routers running firmware version V02....

CVE-2025-29031

CRITICAL CVSS 9.8 Mar 14, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers via a buffer overflow in the fromAddressNat function. Attackers can gain full control of affected devices with...

CVE-2025-29029

CRITICAL CVSS 9.8 Mar 14, 2025

A buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code by sending specially crafted requests to the formSetSpeedWan function. This affects Tenda AC6 routers ru...

CVE-2025-25343

CRITICAL CVSS 9.8 Feb 12, 2025

CVE-2025-25343 is a critical buffer overflow vulnerability in Tenda AC6 router firmware that allows remote code execution. Attackers can exploit this vulnerability to take complete control of affected...

CVE-2024-52714

CRITICAL CVSS 9.8 Nov 19, 2024

A buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code by sending specially crafted requests to the 'fromSetSysTime' function. This affects Tenda AC6 v2.0 rout...

CVE-2023-38823

CRITICAL CVSS 9.8 Nov 20, 2023

A buffer overflow vulnerability in Tenda router firmware allows remote attackers to execute arbitrary code via the formSetCfm function in the httpd service. This affects multiple Tenda router models i...

CVE-2023-40830

CRITICAL CVSS 9.8 Oct 3, 2023

CVE-2023-40830 is a buffer overflow vulnerability in Tenda AC6 routers where the Index parameter lacks length validation. This allows attackers to execute arbitrary code remotely, affecting all users ...

CVE-2023-40837

CRITICAL CVSS 9.8 Aug 30, 2023

This vulnerability allows remote command execution on Tenda AC6 routers by exploiting unfiltered input in the formSetIptv function. Attackers can execute arbitrary commands with root privileges by man...

CVE-2023-40839

CRITICAL CVSS 9.8 Aug 30, 2023

This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC6 routers by sending specially crafted requests to the 'formSetIptv' function. Attackers can gain full control of af...

CVE-2023-40841

CRITICAL CVSS 9.8 Aug 30, 2023

CVE-2023-40841 is a critical buffer overflow vulnerability in Tenda AC6 routers that allows remote attackers to execute arbitrary code or cause denial of service by sending specially crafted requests ...

CVE-2023-40843

CRITICAL CVSS 9.8 Aug 30, 2023

This CVE describes a critical buffer overflow vulnerability in Tenda AC6 routers. Attackers can exploit this to execute arbitrary code or cause denial of service by sending specially crafted requests ...

CVE-2023-40845

CRITICAL CVSS 9.8 Aug 30, 2023

This CVE describes a critical buffer overflow vulnerability in Tenda AC6 routers that allows remote attackers to execute arbitrary code. Attackers can exploit this by sending specially crafted request...

CVE-2023-40848

CRITICAL CVSS 9.8 Aug 30, 2023

CVE-2023-40848 is a critical buffer overflow vulnerability in Tenda AC6 routers that allows remote attackers to execute arbitrary code or cause denial of service. The vulnerability affects users of Te...

CVE-2023-40846

CRITICAL CVSS 9.8 Aug 28, 2023

CVE-2023-40846 is a critical buffer overflow vulnerability in Tenda AC6 routers that allows remote attackers to execute arbitrary code or cause denial of service. The vulnerability exists in the sub_9...

CVE-2023-39670

CRITICAL CVSS 9.8 Aug 18, 2023

This CVE describes a buffer overflow vulnerability in Tenda AC6 routers via the fgets function. Attackers can exploit this to execute arbitrary code or crash the device. Users of Tenda AC6 routers wit...

CVE-2023-38936

CRITICAL CVSS 9.8 Aug 7, 2023

This CVE describes a stack overflow vulnerability in multiple Tenda router models via the speed_dir parameter in the formSetSpeedWan function. Attackers can exploit this to execute arbitrary code or c...

CVE-2022-25445

CRITICAL CVSS 9.8 Mar 18, 2022

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers via a stack overflow in the PowerSaveSet function. Attackers can exploit this by sending specially crafted req...

CVE-2022-25447

CRITICAL CVSS 9.8 Mar 18, 2022

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers via a stack overflow in the openSchedWifi function. Attackers can exploit this by sending specially crafted re...

CVE-2022-25449

CRITICAL CVSS 9.8 Mar 18, 2022

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers by exploiting a stack overflow in the saveParentControlInfo function. Attackers can send specially crafted req...

CVE-2022-25451

CRITICAL CVSS 9.8 Mar 18, 2022

This vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code via a stack overflow in the setstaticroutecfg function. Attackers can exploit this to take complete control of...

CVE-2025-12225

HIGH CVSS 8.8 Oct 27, 2025

This vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the WifiGuestSet HTTP handler. Attackers can exploit this by sending spec...

CVE-2025-60340

HIGH CVSS 7.5 Oct 22, 2025

This vulnerability allows attackers to cause denial of service on Tenda AC6 routers by exploiting buffer overflows in the SetClientState function. Attackers can inject crafted payloads into specific p...

CVE-2025-60341

HIGH CVSS 7.5 Oct 22, 2025

This vulnerability is a stack buffer overflow in Tenda AC6 V2.0 routers through the fast_setting_wifi_set function's ssid parameter. Attackers can exploit this by sending specially crafted input to ca...

CVE-2025-60343

HIGH CVSS 7.5 Oct 22, 2025

This CVE describes multiple buffer overflow vulnerabilities in Tenda AC6 routers that allow attackers to cause denial of service by sending specially crafted payloads to multiple parameters in the Adv...

CVE-2025-60337

HIGH CVSS 7.5 Oct 22, 2025

A buffer overflow vulnerability exists in Tenda AC6 V2.0 routers in the SetSpeedWan function's speed_dir parameter. Attackers can exploit this by sending specially crafted input to cause a Denial of S...

CVE-2025-57528

HIGH CVSS 7.7 Sep 19, 2025

This vulnerability in Tenda AC6 routers allows attackers to cause denial of service through buffer overflow in the formSetCfm function. Attackers can crash the device by sending specially crafted requ...

CVE-2025-55498

HIGH CVSS 7.5 Aug 20, 2025

This buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code by sending specially crafted requests to the time parameter in the fromSetSysTime function. Attackers...

CVE-2025-55483

HIGH CVSS 7.5 Aug 20, 2025

This CVE describes a buffer overflow vulnerability in Tenda AC6 routers, specifically in the formSetMacFilterCfg function. Attackers can exploit it by sending crafted requests with malicious macFilter...

CVE-2025-55503

HIGH CVSS 7.3 Aug 20, 2025

This CVE describes a stack overflow vulnerability in Tenda AC6 routers that allows attackers to execute arbitrary code by sending specially crafted requests to the deviceName parameter in the savePare...

CVE-2025-31355

HIGH CVSS 7.2 Aug 20, 2025

A firmware signature validation bypass vulnerability in Tenda AC6 routers allows attackers to upload malicious firmware updates, leading to arbitrary code execution. This affects Tenda AC6 V5.0 router...

CVE-2025-24322

HIGH CVSS 8.1 Aug 20, 2025

An unsafe default authentication vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code via specially crafted network requests during initial setup. This affects Tenda AC6 V5.0 ...

CVE-2025-50262

HIGH CVSS 7.5 Jul 3, 2025

This buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code or crash the device by sending specially crafted requests to the formSetQosBand function. It affects ...

CVE-2025-50258

HIGH CVSS 8.1 Jul 3, 2025

A buffer overflow vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the SetSysTimeCfg function. This affects Tenda AC6 route...

CVE-2025-50528

HIGH CVSS 7.3 Jun 27, 2025

A buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code or crash the device by sending specially crafted requests to the fromNatStaticSetting function via the p...

CVE-2025-5855

HIGH CVSS 8.8 Jun 9, 2025

A critical stack-based buffer overflow vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code by manipulating the rebootTime parameter. This affects Tenda AC6 routers run...

CVE-2025-5853

HIGH CVSS 8.8 Jun 9, 2025

A critical stack-based buffer overflow vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code by manipulating the remoteIp parameter. This affects Tenda AC6 routers runni...

CVE-2025-29121

HIGH CVSS 7.5 Mar 20, 2025

A stack-based buffer overflow vulnerability exists in Tenda AC6 routers version V15.03.05.16. Attackers can exploit this by sending specially crafted requests to the /goform/fast_setting_wifi_set endp...

CVE-2025-1814

HIGH CVSS 8.8 Mar 2, 2025

This critical vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the /goform/WifiExtraSet endpoint. It affects users of Tenda AC6...

CVE-2024-46450

HIGH CVSS 8.1 Jan 16, 2025

This vulnerability allows attackers to bypass authentication on Tenda AC1200 routers by sending specially crafted web requests. Attackers could gain unauthorized access to the router's administrative ...

CVE-2025-0349

HIGH CVSS 8.8 Jan 9, 2025

A critical stack-based buffer overflow vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code by manipulating the src/mac parameter in the GetParentControlInfo function. ...

CVE-2024-51116

HIGH CVSS 8.8 Nov 5, 2024

A buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code by sending specially crafted requests to the formSetPPTPServer function. This affects Tenda AC6 v2.0 rou...

CVE-2024-10698

HIGH CVSS 8.8 Nov 2, 2024

This critical vulnerability in Tenda AC6 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the device name setting function. Attackers can exploit this wit...

CVE-2023-26976

HIGH CVSS 7.5 Apr 4, 2023

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers by sending a specially crafted request to the WiFi configuration interface. It affects users running Tenda AC6...

CVE-2025-57296

MEDIUM CVSS 6.5 Sep 19, 2025

This CVE describes a command injection vulnerability in Tenda AC6 router firmware that allows attackers to execute arbitrary system commands. The vulnerability affects users of Tenda AC6 routers with ...

CVE-2025-55495

MEDIUM CVSS 6.5 Aug 27, 2025

This buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code by sending specially crafted requests to the fromSetIpMacBind function. It affects users of Tenda AC6...

CVE-2025-44172

MEDIUM CVSS 6.5 Jun 2, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda AC6 routers by exploiting a stack overflow in the setSmartPowerManagement function. Attackers can send specially crafted r...

CVE-2025-25505

MEDIUM CVSS 6.5 Feb 21, 2025

A buffer overflow vulnerability in Tenda AC6 routers allows attackers to execute arbitrary code or cause denial of service by sending specially crafted requests to the affected function. This affects ...

CVE-2024-10697

MEDIUM CVSS 6.3 Nov 2, 2024

This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC6 routers by injecting malicious commands into the 'mac' parameter of the formWriteFacMac API endpoint. Attackers ca...

CVE-2024-10280

MEDIUM CVSS 6.5 Oct 23, 2024

A null pointer dereference vulnerability in Tenda routers allows remote attackers to cause denial of service by manipulating the Content-Length argument in the websReadEvent function. This affects mul...