CVE-2025-32010

A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP response can lead to arbitrary code execution. An attacker can send an HTTP response to trigger this vulnerability.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac6_firmware:02.03.01.110:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac6:5.0:*:*:*:*:*:*:*

History

21 Aug 2025, 18:22

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de desbordamiento de búfer en la pila de la API de nube de Tenda AC6 V5.0 V02.03.01.110. Una respuesta HTTP especialmente manipulada puede provocar la ejecución de código arbitrario. Un atacante puede enviar una respuesta HTTP para activar esta vulnerabilidad.
References () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2168 - () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2168 - Third Party Advisory
First Time Tenda ac6
Tenda ac6 Firmware
Tenda
CPE cpe:2.3:o:tenda:ac6_firmware:02.03.01.110:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac6:5.0:*:*:*:*:*:*:*

20 Aug 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-20 14:15

Updated : 2025-08-21 18:22


NVD link : CVE-2025-32010

Mitre link : CVE-2025-32010

CVE.ORG link : CVE-2025-32010


JSON object : View

Products Affected

tenda

  • ac6
  • ac6_firmware
CWE
CWE-121

Stack-based Buffer Overflow