CVE-2025-1819: Tenda AC7 1200M telnet TendaTelnet os command injection
Published Mar 2, 2025
·Updated
A vulnerability, which was classified as critical, was found in Tenda AC7 1200M 15.03.06.44. Affected is the function TendaTelnet of the file /goform/telnet. The manipulation of the argument lanip leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda AC7 1200M
All of the following
Tenda AC7 firmware=15.03.06.44
Tenda AC7
Event History
Mar 2, 2025
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-1819?
CVE-2025-1819 is classified as a critical vulnerability.
2
How do I fix CVE-2025-1819?
To fix CVE-2025-1819, update your Tenda AC7 1200M firmware to the latest version that addresses this vulnerability.
3
What does CVE-2025-1819 affect?
CVE-2025-1819 affects the Tenda AC7 1200M model specifically in the TendaTelnet function.
4
What type of attack can exploit CVE-2025-1819?
CVE-2025-1819 can be exploited through remote OS command injection.
5
Can CVE-2025-1819 be exploited remotely?
Yes, CVE-2025-1819 allows for remote exploitation, making it particularly dangerous.