First published: Fri Jan 10 2025(Updated: )
Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote arbitrary code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda AC7, AC9, and AC10 Routers |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22949 is classified as a critical vulnerability due to its potential for remote arbitrary code execution.
To address CVE-2025-22949, update the Tenda AC9 firmware to a version that patches the command injection vulnerability.
CVE-2025-22949 specifically affects the Tenda AC9 V1.0 firmware version 15.03.05.19.
CVE-2025-22949 is a command injection vulnerability that allows attackers to execute arbitrary commands.
Yes, CVE-2025-22949 can be exploited remotely, allowing attackers to gain unauthorized access to the device.