CVE-2025-22949: Command Injection
Published Jan 10, 2025
·Updated
Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote arbitrary code execution.
Affected Software
1 affected component
Tenda Ac9
Event History
Jan 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-22949?
CVE-2025-22949 is classified as a critical vulnerability due to its potential for remote arbitrary code execution.
2
How do I fix CVE-2025-22949?
To address CVE-2025-22949, update the Tenda AC9 firmware to a version that patches the command injection vulnerability.
3
What systems are affected by CVE-2025-22949?
CVE-2025-22949 specifically affects the Tenda AC9 V1.0 firmware version 15.03.05.19.
4
What type of vulnerability is CVE-2025-22949?
CVE-2025-22949 is a command injection vulnerability that allows attackers to execute arbitrary commands.
5
Can CVE-2025-22949 be exploited remotely?
Yes, CVE-2025-22949 can be exploited remotely, allowing attackers to gain unauthorized access to the device.