9.8

CVE-2025-27129

An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tenda ≫ Ac6 Firmware Version 02.03.01.110
   Tenda ≫ Ac6 Version 5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.11% 0.798
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Cisco Talos 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-288 Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

https://talosintelligence.com/vulnerability_reports/TALOS-2025-2165
Third Party Advisory
https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2165