Back to overview

CVE-2025-27129

CRITICAL
9.8
CVSS 3.1
Description
An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability.

Metadata

CVE ID
CVE-2025-27129
State
PUBLISHED
Assigner
talos
Reserved
2025-03-31 11:53 UTC
Published
2025-08-20 13:09 UTC
Last updated
2025-11-03 18:08 UTC
Primary CWE
CWE-288
CWE-288: Authentication Bypass Using an Alternate Path or Ch…
Vendor / Product
Tenda / AC6 V5.0
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Tenda AC6 V5.0 V02.03.01.110
Weakness (CWE)
CWESourceDescription
CWE-288 cna CWE-288: Authentication Bypass Using an Alternate Path or Channel
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References (1)
Back to overview