CVE-2025-46035: Tenda AC6 Firmware

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTime and schedEndTime parameters in an unauthenticated HTTP GET request to the /goform/openSchedWifi endpoint

Affected products

  • Tenda AC6 Firmware: version 15.03.05.16 only

Published 2025-06-12. Last modified 2026-07-05.