CVE-2025-24322 Details
Description
An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted network request can lead to arbitrary code execution. An attacker can browse to the device to trigger this vulnerability.
A vulnerability exists in the Tenda AC6 router, specifically in version 5.0 V02.03.01.110, due to an unsafe default authentication process during the initial setup. The setup wizard fails to require a web portal username and password, allowing anyone on the local network to gain full administrative access without authentication. This oversight can be exploited to execute arbitrary code, including the installation of malicious firmware.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2163 | CVE | |
| https://talosintelligence.com/vulnerability_reports/TALOS-2025-2163 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-304 | Missing Critical Step in Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tenda ac6 firmware | 02.03.01.110 |
CPE
Remediation
| |
| tenda ac6 | 5.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Aug 21, 2025 | Initial Analysis | [email protected] |
| Aug 20, 2025 | New CVE Received | [email protected] |