Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the limitSpeed, deviceId, and limitSpeedUp parameters.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 24 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Tenda ac6 Firmware
         | 
|
| Weaknesses | CWE-120 | |
| CPEs | cpe:2.3:h:tenda:ac6:2.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac6_firmware:15.03.06.50:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Tenda ac6 Firmware
         | 
Thu, 23 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        cvssV3_1
         
 
  | 
Thu, 23 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Tenda
         Tenda ac6  | 
|
| Vendors & Products | 
        
        Tenda
         Tenda ac6  | 
Wed, 22 Oct 2025 17:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the limitSpeed, deviceId, and limitSpeedUp parameters. | |
| References | 
         | 
Status: PUBLISHED
Assigner: mitre
Published: 2025-10-22T00:00:00.000Z
Updated: 2025-10-28T15:07:31.877Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60340
Updated: 2025-10-23T15:35:59.533Z
Status : Modified
Published: 2025-10-22T18:15:35.000
Modified: 2025-10-28T16:15:38.817
Link: CVE-2025-60340
No data.