First published: Fri Feb 21 2025(Updated: )
There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25507 is rated as critical due to its potential for remote command execution.
To mitigate CVE-2025-25507, update Tenda AC6 firmware to the latest version provided by the vendor.
CVE-2025-25507 can be exploited to execute arbitrary commands on the device remotely.
CVE-2025-25507 affects Tenda AC6 firmware version 15.03.05.16_multi and possibly earlier versions.
Check if your Tenda AC6 device is running firmware version 15.03.05.16_multi or earlier to confirm vulnerability to CVE-2025-25507.