CVE-2025-44865: Command Injection
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the enable parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44865?
CVE-2025-44865 is rated as a high severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2025-44865?
To fix CVE-2025-44865, update the Tenda W20E firmware to the latest version that addresses the command injection issue.
Who is affected by CVE-2025-44865?
Users of Tenda W20E routers running firmware version V15.11.0.6 are affected by CVE-2025-44865.
What can attackers do with CVE-2025-44865?
Attackers can exploit CVE-2025-44865 to execute arbitrary commands on the affected Tenda W20E device.
Is CVE-2025-44865 publicly known?
Yes, CVE-2025-44865 is a publicly disclosed vulnerability and details have been made available in security advisories.