CVE-2025-5852: Tenda AC6 setPptpUserList formSetPPTPUserList buffer overflow
A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function formSetPPTPUserList of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5852?
CVE-2025-5852 is classified as a critical vulnerability.
How do I fix CVE-2025-5852?
To fix CVE-2025-5852, update the Tenda AC6 firmware to a version that is not affected by this vulnerability.
What causes the CVE-2025-5852 vulnerability?
CVE-2025-5852 is caused by a buffer overflow in the formSetPPTPUserList function of the Tenda AC6 firmware.
Can CVE-2025-5852 be exploited remotely?
Yes, CVE-2025-5852 can be exploited remotely by manipulating the argument list.
What devices are affected by CVE-2025-5852?
CVE-2025-5852 affects Tenda AC6 devices running firmware version 15.03.05.16.