CVE-2025-70252: High severity Tenda AC6V2.0 vulnerability
An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70252?
CVE-2025-70252 is classified as a high-severity vulnerability due to its potential to cause stack overflow exploitation.
How do I fix CVE-2025-70252?
To fix CVE-2025-70252, update the Tenda AC6V2.0 firmware to the latest version that addresses this vulnerability.
What devices are affected by CVE-2025-70252?
CVE-2025-70252 affects the Tenda AC6V2.0 running version V15.03.06.23_multi of its firmware.
What kind of vulnerability is CVE-2025-70252?
CVE-2025-70252 is a stack overflow vulnerability that arises from a lack of size checking during string operations.
Who discovered CVE-2025-70252?
CVE-2025-70252 was discovered in the Tenda AC6V2.0 router firmware.