CVE-2025-5853: Tenda AC6 SetRemoteWebCfg formSetSafeWanWebMan stack-based overflow
Published Jun 9, 2025
·Updated
A vulnerability classified as critical was found in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg. The manipulation of the argument remoteIp leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
All of the following
Tenda Ac6 Firmware=15.03.05.16
Tenda AC6=1.0
Event History
Jun 9, 2025
CVE Published
via MITRE·12:31 AM
Data Sourced
via MITRE·12:31 AM
DescriptionSeverityWeakness
Mar 3, 57425
Event
via FIRST·03:04 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-5853?
CVE-2025-5853 is classified as a critical vulnerability.
2
What does CVE-2025-5853 affect?
CVE-2025-5853 affects the Tenda AC6 firmware version 15.03.05.16.
3
How do I fix CVE-2025-5853?
To fix CVE-2025-5853, upgrade the Tenda AC6 firmware to a patched version.
4
What type of vulnerability is CVE-2025-5853?
CVE-2025-5853 is a stack-based buffer overflow vulnerability.
5
Can CVE-2025-5853 be exploited remotely?
Yes, CVE-2025-5853 can be exploited remotely through manipulation of the remoteIp argument.