CVE-2025-15048: Tenda WH450 HTTP Request CheckTools command injection
A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request Handler. Executing a manipulation of the argument ipaddress can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15048?
CVE-2025-15048 is rated as a high severity vulnerability due to its potential for remote command injection.
How do I fix CVE-2025-15048?
To mitigate CVE-2025-15048, you should update the Tenda WH450 firmware to the latest version provided by the vendor.
What does CVE-2025-15048 affect?
CVE-2025-15048 affects the Tenda WH450 router specifically in the HTTP Request Handler component.
Can CVE-2025-15048 be exploited remotely?
Yes, CVE-2025-15048 can be exploited remotely by manipulating the ipaddress parameter.
What type of attack does CVE-2025-15048 enable?
CVE-2025-15048 enables command injection attacks through the affected component.