CVE-2025-14636: Tenda AX9 httpd image_check weak hash
A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function imagecheck of the component httpd. The manipulation results in use of weak hash. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is indicated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14636?
CVE-2025-14636 is considered to be of high severity due to its potential to allow remote attacks with complex exploitation.
How do I fix CVE-2025-14636?
To fix CVE-2025-14636, it is recommended to update the Tenda AX9 firmware to the latest version provided by the vendor.
What component is affected by CVE-2025-14636?
CVE-2025-14636 affects the httpd component's image_check function in the Tenda AX9 router.
What type of vulnerability is CVE-2025-14636?
CVE-2025-14636 is a security vulnerability that results in the use of weak hashing algorithms.
Can CVE-2025-14636 be exploited remotely?
Yes, CVE-2025-14636 can be exploited remotely, making it critical to implement mitigations promptly.