First published: Thu Feb 20 2025(Updated: )
Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the doSystemCmd function, causing an arbitrary command execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda AC7, AC9, and AC10 Routers | =V15.03.06.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25675 is considered a high severity command injection vulnerability.
To fix CVE-2025-25675, update the Tenda AC10 firmware to the latest version that addresses this vulnerability.
CVE-2025-25675 is caused by improper handling of user input in the formexeCommand function.
CVE-2025-25675 affects users of the Tenda AC10 running firmware version V15.03.06.23.
The potential impacts of CVE-2025-25675 include unauthorized command execution on the vulnerable device.