CVE-2025-60340
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-22

Last updated on: 2025-10-28

Assigner: MITRE

Description
Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the limitSpeed, deviceId, and limitSpeedUp parameters.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-22
Last Modified
2025-10-28
Generated
2026-05-07
AI Q&A
2025-10-22
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
tenda ac6_firmware 15.03.06.50
tenda ac6 2.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability involves multiple buffer overflows in the SetClientState function of Tenda AC6 version 15.03.06.50. Attackers can exploit this by injecting a specially crafted payload into the limitSpeed, deviceId, and limitSpeedUp parameters, which causes the device to malfunction. [1]


How can this vulnerability impact me? :

Exploiting this vulnerability can cause a Denial of Service (DoS) condition, meaning the affected device may crash or become unresponsive, disrupting network connectivity and services relying on the Tenda AC6 router. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart