Vulnerability Description
Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.
CVSS Score
7.3
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ac6 Firmware | 15.03.06.23_multi |
| Tenda | Ac6 | 2.0 |
Related Weaknesses (CWE)
References
- https://github.com/SolitaryGrass/IoT_vuln/blob/main/tenda/AC6/AC6V2.0RTL_V15.03.ExploitThird Party Advisory
FAQ
What is CVE-2025-55503?
CVE-2025-55503 is a vulnerability with a CVSS score of 7.3 (HIGH). Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.
How severe is CVE-2025-55503?
CVE-2025-55503 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-55503?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ac6 Firmware, Tenda Ac6.