CVE-2025-70252Disclosure(tenda / ac6)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac6
  • ac6_firmware

Threat summary

  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-02); latest day: 2
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
ac6ac6_firmware

2 versions affected across 2 products

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-03-02: 3Mentions · 2026-03-05: 1Mentions · 2026-03-06: 2Technical Details · 2026-03-02: 2Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 203-0203-0503-06
Signal classification1 categories
Disclosure
6100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-023
Disclosure3
2026-03-051
Disclosure1
2026-03-062
Disclosure2
Full discourse6 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Tenda AC6, Stack Overflow, #CVE-2025-70252 (High) https://dailycve.com/tenda-ac6-stack-overflow-cve-2025-70252-high/

    Post summary

    This tweet announces the discovery of a high‑severity stack overflow vulnerability (CVE‑2025‑70252) in the Tenda AC6 router and links to an external article for details.

    00000136
    164 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-70252 (CVSS:7.5, HIGH) is Undergoing Analysis. An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable..https://nvd.nist.gov/vuln/detail/CVE-2025-70252 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE-2025-70252, a high‑severity vulnerability in Tenda AC6V2.0 firmware with controllable parameters, and indicates it is currently under analysis, without providing PoC or exploitation details.

    0000056
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-70252 (CVSS:7.5, HIGH) is Undergoing Analysis. An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable..https://nvd.nist.gov/vuln/detail/CVE-2025-70252 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2025‑70252 with its CVSS score and technical details, indicating analysis is underway but no evidence of exploitation or PoC is presented.

    0000040
    173 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-70252 An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they w… https://www.cve.org/CVERecord?id=CVE-2025-70252 ----- Traducción: Se descubrió un pr… http://infoflow.cloud`

    Post summary

    CVE-2025-70252 is a vulnerability in Tenda AC6V2.0 firmware’s /goform/WifiWpsStart endpoint, where controllable index and mode parameters could lead to a buffer overflow via sprintf.

    0000096
    55 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Tenda AC6 (CVE-2025-70252) https://vuldb.com/?id.348419

    Post summary

    The post reports that the severity of CVE-2025-70252, a vulnerability in the Tenda AC6, has been increased, with details posted on vuldb.com.

    00000166
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-70252 An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they w… https://www.cve.org/CVERecord?id=CVE-2025-70252

    Post summary

    A vulnerability was identified in Tenda AC6V2.0’s /goform/WifiWpsStart, where controllable index and mode parameters could trigger a buffer overflow via sprintf.

    00000274
    56.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac62.0--
OStendaac6_firmware15.03.06.23_multi--

Explore more