CVE-2025-5854: Tenda AC6 AdvSetLanip fromadvsetlanip buffer overflow
Published Jun 9, 2025
·Updated
A vulnerability, which was classified as critical, has been found in Tenda AC6 15.03.05.16. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
All of the following
Tenda Ac6 Firmware=15.03.05.16
Tenda AC6=1.0
Event History
Jun 9, 2025
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
DescriptionSeverityWeakness
Mar 3, 57425
Event
via FIRST·07:31 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-5854?
CVE-2025-5854 has been classified as a critical vulnerability.
2
How do I fix CVE-2025-5854?
To fix CVE-2025-5854, update the Tenda AC6 firmware to a version that does not contain this vulnerability.
3
What exploitation vector does CVE-2025-5854 use?
CVE-2025-5854 can be exploited remotely by manipulating the lanMask argument.
4
What kind of vulnerability is CVE-2025-5854?
CVE-2025-5854 is a buffer overflow vulnerability found in the function fromadvsetlanip.
5
Which version of Tenda AC6 is affected by CVE-2025-5854?
CVE-2025-5854 affects Tenda AC6 firmware version 15.03.05.16.