ID

VAR-202510-2248


CVE

CVE-2025-60342


TITLE

Tenda AC6 addressNat function stack buffer overflow vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-27902

DESCRIPTION

Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. The Tenda AC6 is a dual-band wireless router from Tenda, designed specifically for home users with 100Mbps fiber optic connections. This vulnerability stems from the page parameter in the addressNat function failing to properly validate the length of the input data

Trust: 1.44

sources: NVD: CVE-2025-60342 // CNVD: CNVD-2025-27902

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-27902

AFFECTED PRODUCTS

vendor:tendamodel:ac6scope:eqversion:15.03.06.50

Trust: 1.0

vendor:tendamodel:ac6scope:eqversion:v2.015.03.06.50

Trust: 0.6

sources: CNVD: CNVD-2025-27902 // NVD: CVE-2025-60342

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2025-60342
value: HIGH

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-60342
value: HIGH

Trust: 1.0

CNVD: CNVD-2025-27902
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-27902
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2025-60342
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 2.0

sources: CNVD: CNVD-2025-27902 // NVD: CVE-2025-60342 // NVD: CVE-2025-60342

PROBLEMTYPE DATA

problemtype:CWE-121

Trust: 1.0

problemtype:CWE-787

Trust: 1.0

sources: NVD: CVE-2025-60342

EXTERNAL IDS

db:NVDid:CVE-2025-60342

Trust: 1.6

db:CNVDid:CNVD-2025-27902

Trust: 0.6

sources: CNVD: CNVD-2025-27902 // NVD: CVE-2025-60342

REFERENCES

url:https://github.com/z472421519/binaryaudit/blob/main/poc/bof/tenda/addressnat/addressnat.md

Trust: 1.6

sources: CNVD: CNVD-2025-27902 // NVD: CVE-2025-60342

SOURCES

db:CNVDid:CNVD-2025-27902
db:NVDid:CVE-2025-60342

LAST UPDATE DATE

2025-11-19T23:14:42.682000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-27902date:2025-11-14T00:00:00
db:NVDid:CVE-2025-60342date:2025-10-23T15:15:43.913

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-27902date:2025-11-14T00:00:00
db:NVDid:CVE-2025-60342date:2025-10-22T18:15:35.270