VulnSea

ac6_firmware vulnerabilities

CVEs whose affected-version data names the ac6_firmware package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-8265Medium· 4.7
4mo ago

A security vulnerability has been detected in Tenda AC6 15.03.06.23

A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os comman…

Sunlittenda · ac6_firmwareEPSS 4.4%via NVD
CVE-2026-8264Medium· 6.3
4mo ago

A weakness has been identified in Tenda AC6 15.03.06.23

A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl…

Sunlittenda · ac6_firmwareEPSS 2.9%via NVD
CVE-2026-8259Medium· 4.7
4mo ago

A vulnerability has been found in Tenda AC6 2.0/15.03.06.23

A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exp…

Sunlittenda · ac6_firmwareEPSS 4.4%via NVD
CVE-2025-52221Critical· 9.8
5mo ago

Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters.

Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters.

Midnighttenda · ac6_firmwareEPSS 0.39%via NVD
CVE-2022-37176Critical· 9.8
4y ago

Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard.

Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard.

Midnighttendacn · ac6_firmwareEPSS 0.90%via NVD
CVE-2022-36552High· 7.5
4y ago

Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.

Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.

Twilighttendacn · ac6_firmwareEPSS 0.70%via NVD
ac6_firmware vulnerabilities (CVEs) · VulnSea