CVE-2025-6887: Tenda AC5 SetSysTimeCfg stack-based overflow
A vulnerability was found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/SetSysTimeCfg. The manipulation of the argument time/timeZone leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6887?
CVE-2025-6887 is classified as critical due to the potential for stack-based buffer overflow.
How do I fix CVE-2025-6887?
To mitigate CVE-2025-6887, update the Tenda AC5 to the latest firmware version where this vulnerability is resolved.
What are the potential impacts of CVE-2025-6887?
The exploitation of CVE-2025-6887 can allow an attacker to execute arbitrary code remotely on affected devices.
Who is affected by CVE-2025-6887?
CVE-2025-6887 affects users of Tenda AC5 running firmware version 15.03.06.47.
How can CVE-2025-6887 be exploited?
An attacker can exploit CVE-2025-6887 by manipulating the time or timeZone arguments of the /goform/SetSysTimeCfg file.