CVE-2025-70252

HIGH

Tenda AC6V2.0 V15.03.06.23 - Buffer Overflow

Title source: llm
STIX 2.1

Description

An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow vulnerability.

Scores

CVSS v3 7.5
EPSS 0.0002
EPSS Percentile 6.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-121
Status published
Products (1)
tenda/ac6_firmware 15.03.06.23_multi
Published Mar 02, 2026
Tracked Since Mar 03, 2026