CVE-2025-15255: Tenda W6-S R7websSsecurityHandler httpd stack-based overflow
A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of the component R7websSsecurityHandler. Executing a manipulation of the argument Cookie can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15255?
CVE-2025-15255 has a critical severity level due to its potential for remote exploitation leading to stack-based buffer overflow.
What are the potential impacts of CVE-2025-15255?
CVE-2025-15255 can allow attackers to gain unauthorized access and execute arbitrary code through vulnerable systems.
How do I fix CVE-2025-15255?
To fix CVE-2025-15255, users should update the Tenda W6-S firmware to the latest version provided by the manufacturer.
Who is affected by CVE-2025-15255?
CVE-2025-15255 affects Tenda W6-S devices running version 1.0.0.4(510) of the firmware.
Can CVE-2025-15255 be exploited remotely?
Yes, CVE-2025-15255 can be exploited remotely, making it particularly dangerous for connected devices.