CVE-2025-14286: Tenda AC9 Configuration File DownloadCfg.jpg information disclosure
A vulnerability was determined in Tenda AC9 15.03.05.14multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/DownloadCfg.jpg of the component Configuration File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14286?
CVE-2025-14286 is classified as a medium severity vulnerability due to potential information disclosure.
How do I fix CVE-2025-14286?
To mitigate CVE-2025-14286, update the Tenda AC9 firmware to the latest version provided by the vendor.
What type of vulnerability is CVE-2025-14286?
CVE-2025-14286 is an information disclosure vulnerability affecting the Configuration File Handler component.
Which devices are affected by CVE-2025-14286?
CVE-2025-14286 specifically affects the Tenda AC9 router running firmware version 15.03.05.14_multi.
Can CVE-2025-14286 be exploited remotely?
Yes, CVE-2025-14286 can be exploited remotely, potentially allowing unauthorized access to sensitive information.