CVE-2025-27129

An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac6_firmware:02.03.01.110:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac6:5.0:*:*:*:*:*:*:*

History

21 Aug 2025, 18:24

Type Values Removed Values Added
First Time Tenda
Tenda ac6 Firmware
Tenda ac6
Summary
  • (es) Existe una vulnerabilidad de omisión de autenticación en la función de autenticación HTTP de Tenda AC6 V5.0 V02.03.01.110. Una solicitud HTTP especialmente manipulada puede provocar la ejecución de código arbitrario. Un atacante puede enviar paquetes para activar esta vulnerabilidad.
References () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2165 - () https://talosintelligence.com/vulnerability_reports/TALOS-2025-2165 - Third Party Advisory
CPE cpe:2.3:o:tenda:ac6_firmware:02.03.01.110:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac6:5.0:*:*:*:*:*:*:*

20 Aug 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-20 14:15

Updated : 2025-08-21 18:24


NVD link : CVE-2025-27129

Mitre link : CVE-2025-27129

CVE.ORG link : CVE-2025-27129


JSON object : View

Products Affected

tenda

  • ac6
  • ac6_firmware
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel