CVE-2025-25632: Command Injection
Published Mar 5, 2025
·Updated
Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.
Affected Software
3 affected components
Tenda Ac15
All of the following
Tenda ac15 firmware=15.03.05.19
Tenda Ac15
Event History
Mar 5, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25632?
CVE-2025-25632 is considered a critical vulnerability due to its potential for unauthorized command execution.
2
How do I fix CVE-2025-25632?
To fix CVE-2025-25632, ensure that you update your Tenda AC15 firmware to the latest version available from the vendor.
3
What type of vulnerability is CVE-2025-25632?
CVE-2025-25632 is a command injection vulnerability affecting the Tenda AC15 router.
4
Who is affected by CVE-2025-25632?
Users of the Tenda AC15 router with firmware version 15.03.05.19 are affected by CVE-2025-25632.
5
Is CVE-2025-25632 being actively exploited?
As of now, there are no confirmed reports of active exploitation for CVE-2025-25632, but the risk remains due to its nature.