CVE-2025-27129

An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac6_firmware:02.03.01.110:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac6:5.0:*:*:*:*:*:*:*

History

21 Aug 2025, 18:24

Type Values Removed Values Added
CPE cpe:2.3:o:tenda:ac6_firmware:02.03.01.110:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac6:5.0:*:*:*:*:*:*:*
Summary
  • (es) Existe una vulnerabilidad de omisión de autenticación en la función de autenticación HTTP de Tenda AC6 V5.0 V02.03.01.110. Una solicitud HTTP especialmente manipulada puede provocar la ejecución de código arbitrario. Un atacante puede enviar paquetes para activar esta vulnerabilidad.
First Time Tenda ac6
Tenda ac6 Firmware
Tenda
References () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2165 - () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2165 - Third Party Advisory

20 Aug 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-20 14:15

Updated : 2025-08-21 18:24


NVD link : CVE-2025-27129

Mitre link : CVE-2025-27129

CVE.ORG link : CVE-2025-27129


JSON object : View

Products Affected

tenda

  • ac6
  • ac6_firmware
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel