216.73.216.226

CVE-2025-15255

· Published 30/12/2025 16:15 · Modified 31/12/2025 20:42

Labels: CVE-2025-15255 2025-12-30CVE-2025-15255CWE-119[email protected]

Essential information

Published
30/12/2025 16:15
Modified
31/12/2025 20:42
Author
Creator
CVSS
8.9 HIGH (v3) 8.9 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of the component R7websSsecurityHandler. Executing manipulation of the argument Cookie can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tenda / w6-s cpe:2.3:a:tenda:w6-s:1.0.0.4(510):*:*:*:*:*:*:*
tenda / w6-s cpe:2.3:a:tenda:w6-s:*:*:*:*:*:*:*:*

References