A vulnerability was found in Tenda AC6 15.03.06.23. It has been declared as critical. This impacts the function saveParentControlInfo. The manipulation of the argument deviceName results in stack-based buffer overflow.

This vulnerability is reported as CVE-2025-55503. The attack can be launched remotely. No exploit exists.