CVE-2025-24496

An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.110. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets to trigger this vulnerability.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac6_firmware:02.03.01.110:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac6:5.0:*:*:*:*:*:*:*

History

21 Aug 2025, 18:24

Type Values Removed Values Added
First Time Tenda
Tenda ac6 Firmware
Tenda ac6
CPE cpe:2.3:o:tenda:ac6_firmware:02.03.01.110:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac6:5.0:*:*:*:*:*:*:*
Summary
  • (es) Existe una vulnerabilidad de divulgación de información en la función /goform/getproductInfo de Tenda AC6 V5.0 V02.03.01.110. Los paquetes de red especialmente manipulados pueden provocar la divulgación de información confidencial. Un atacante puede enviar paquetes para activar esta vulnerabilidad.
References () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2164 - () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2164 - Third Party Advisory

20 Aug 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-20 14:15

Updated : 2025-08-21 18:24


NVD link : CVE-2025-24496

Mitre link : CVE-2025-24496

CVE.ORG link : CVE-2025-24496


JSON object : View

Products Affected

tenda

  • ac6
  • ac6_firmware
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel