CVE-2025-57528: Tenda AC6 Firmware
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered in Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01 allowing attackers to cause a denial of service via the funcname, funcpara1, funcpara2 parameters to the formSetCfm function (uri path: SetCfm).
Affected products
- Tenda AC6 Firmware: version 15.03.05.16 only
Published 2025-09-19. Last modified 2026-06-17.