CVE-2025-31355 Details
Description
A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted malicious file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
A vulnerability has been identified in the firmware signature validation process of the Tenda AC6 V5.0 router, specifically in version V02.03.01.110. This vulnerability allows for arbitrary code execution by exploiting the firmware update mechanism. An attacker can upload a specially crafted malicious file that bypasses integrity checks, leading to unauthorized code execution on the device.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2161 | CVE | |
| https://talosintelligence.com/vulnerability_reports/TALOS-2025-2161 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-494 | Download of Code Without Integrity Check | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tenda ac6 firmware | 02.03.01.110 |
CPE
Remediation
| |
| tenda ac6 | 5.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Aug 21, 2025 | Initial Analysis | [email protected] |
| Aug 20, 2025 | New CVE Received | [email protected] |