AC6
Tenda- Product type
- Operating system
- Catalog vulnerabilities
- 36
Severity across 18 analyzed records
en
Severity across 18 analyzed records
Verify to analyze this security profile
As of 10/06/2026, within CyStack's analyzed data, AC6 has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of AC6 and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-8265Tenda AC6 httpd getLogFile get_log_file os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published05/11/2026 | SeverityMedium |
CVE-2026-8264Tenda AC6 httpd WifiApScan formWifiApScan os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published05/11/2026 | SeverityMedium |
CVE-2026-8263Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published05/11/2026 | SeverityMedium |
CVE-2026-8259Tenda AC6 httpd telnet os command injection | Exploitation statusPublic exploit | FixNot confirmed | Published05/11/2026 | SeverityMedium |
CVE-2026-4961Tenda AC6 POST Request QuickIndex formQuickIndex stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/27/2026 | SeverityHigh |
CVE-2026-4960Tenda AC6 POST Request WizardHandle fromWizardHandle stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/27/2026 | SeverityHigh |
CVE-2025-12225Tenda AC6 HTTP Request WifiGuestSet stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published10/27/2025 | SeverityHigh |
CVE-2025-7914Tenda AC6 httpd setparentcontrolinfo buffer overflow | Exploitation statusNot known exploited | FixNot confirmed | Published07/21/2025 | SeverityHigh |
CVE-2025-5855Tenda AC6 SetRebootTimer formSetRebootTimer stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/09/2025 | SeverityHigh |
CVE-2025-5854Tenda AC6 AdvSetLanip fromadvsetlanip buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/09/2025 | SeverityHigh |
CVE-2025-5853Tenda AC6 SetRemoteWebCfg formSetSafeWanWebMan stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/09/2025 | SeverityHigh |
CVE-2025-5852Tenda AC6 setPptpUserList formSetPPTPUserList buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published06/09/2025 | SeverityHigh |
CVE-2025-1814Tenda AC6 WifiExtraSet stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/02/2025 | SeverityHigh |
CVE-2025-0349Tenda AC6 GetParentControlInfo stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published01/09/2025 | SeverityHigh |
CVE-2024-10698Tenda AC6 SetOnlineDevName formSetDeviceName stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published11/02/2024 | SeverityHigh |
CVE-2024-10697Tenda AC6 API Endpoint WriteFacMac formWriteFacMac command injection | Exploitation statusPublic exploit | FixNot confirmed | Published11/02/2024 | SeverityMedium |
CVE-2024-10280Tenda AC6/AC7/AC8/AC9/AC10/AC10U/AC15/AC18/AC500/AC1206 GetIPTV websReadEvent null pointer dereference | Exploitation statusPublic exploit | FixNot confirmed | Published10/23/2024 | SeverityHigh |
CVE-2021-40546 | Exploitation statusPublic exploit | FixNot confirmed | Published09/05/2023 | SeverityUnknown |
CVE-2023-40848 | Exploitation statusNot known exploited | FixNot confirmed | Published08/30/2023 | SeverityUnknown |
CVE-2023-40844 | Exploitation statusNot known exploited | FixNot confirmed | Published08/30/2023 | SeverityUnknown |
CVE-2023-40843 | Exploitation statusNot known exploited | FixNot confirmed | Published08/30/2023 | SeverityUnknown |
CVE-2023-40840 | Exploitation statusNot known exploited | FixNot confirmed | Published08/30/2023 | SeverityUnknown |
CVE-2023-40845 | Exploitation statusNot known exploited | FixNot confirmed | Published08/30/2023 | SeverityUnknown |
CVE-2023-40839 | Exploitation statusNot known exploited | FixNot confirmed | Published08/30/2023 | SeverityUnknown |
CVE-2023-40841 | Exploitation statusNot known exploited | FixNot confirmed | Published08/30/2023 | SeverityUnknown |
CVE-2023-40838 | Exploitation statusNot known exploited | FixNot confirmed | Published08/30/2023 | SeverityUnknown |
CVE-2023-40842 | Exploitation statusNot known exploited | FixNot confirmed | Published08/30/2023 | SeverityUnknown |
CVE-2023-40837 | Exploitation statusNot known exploited | FixNot confirmed | Published08/30/2023 | SeverityUnknown |
CVE-2023-40847 | Exploitation statusNot known exploited | FixNot confirmed | Published08/30/2023 | SeverityUnknown |
CVE-2023-40846 | Exploitation statusNot known exploited | FixNot confirmed | Published08/28/2023 | SeverityUnknown |
CVE-2023-39670 | Exploitation statusNot known exploited | FixNot confirmed | Published08/18/2023 | SeverityUnknown |
CVE-2023-38931 | Exploitation statusPublic exploit | FixNot confirmed | Published08/07/2023 | SeverityUnknown |
CVE-2023-38936 | Exploitation statusPublic exploit | FixNot confirmed | Published08/07/2023 | SeverityUnknown |
CVE-2023-38933 | Exploitation statusPublic exploit | FixNot confirmed | Published08/07/2023 | SeverityUnknown |
CVE-2023-38937 | Exploitation statusPublic exploit | FixNot confirmed | Published08/07/2023 | SeverityUnknown |
CVE-2023-2923Tenda AC6 fromDhcpListClient stack-based overflow | Exploitation statusPublic exploit | FixNot confirmed | Published05/27/2023 | SeverityMedium |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan