CVE-2025-5855: Tenda AC6 SetRebootTimer formSetRebootTimer stack-based overflow
Published Jun 9, 2025
·Updated
A vulnerability, which was classified as critical, was found in Tenda AC6 15.03.05.16. This affects the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument rebootTime leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
All of the following
Tenda Ac6 Firmware=15.03.05.16
Tenda AC6=1.0
Event History
Jun 9, 2025
CVE Published
via MITRE·01:31 AM
Data Sourced
via MITRE·01:31 AM
DescriptionSeverityWeakness
Mar 4, 57425
Event
via FIRST·08:53 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-5855?
CVE-2025-5855 is classified as a critical vulnerability.
2
How do I fix CVE-2025-5855?
To fix CVE-2025-5855, update the Tenda AC6 firmware to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2025-5855?
CVE-2025-5855 is a stack-based buffer overflow vulnerability.
4
Which devices are affected by CVE-2025-5855?
CVE-2025-5855 affects the Tenda AC6 firmware version 15.03.05.16.
5
What component of Tenda AC6 does CVE-2025-5855 impact?
CVE-2025-5855 impacts the function formSetRebootTimer in the file /goform/SetRebootTimer.