Executive brief
The Tenda AC6 router is vulnerable to a critical security flaw in its web management interface. An attacker can exploit this to crash the device or potentially take full control of the router remotely. This could lead to the interception of internet traffic, unauthorized access to the local network, or a complete loss of internet connectivity for the home or office.
Technical details
A stack-based buffer overflow exists in the 'httpd' executable of the Tenda AC6 router, specifically within the 'formSetCfm' function (associated with the /SetCfm URI path). The vulnerability is triggered by insufficient length validation of the 'funcname', 'funcpara1', and 'funcpara2' parameters received via HTTP requests. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to the device. Successful exploitation can lead to arbitrary code execution (RCE) or a denial-of-service (DoS) condition. The issue is confirmed in firmware version 15.03.05.16_multi.
Affected products
- Tenda AC6 15.03.05.16_multi
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory