First published: Thu May 01 2025(Updated: )
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the enable parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda W20e Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-44865 is rated as a high severity vulnerability due to its potential for arbitrary command execution.
To fix CVE-2025-44865, update the Tenda W20E firmware to the latest version that addresses the command injection issue.
Users of Tenda W20E routers running firmware version V15.11.0.6 are affected by CVE-2025-44865.
Attackers can exploit CVE-2025-44865 to execute arbitrary commands on the affected Tenda W20E device.
Yes, CVE-2025-44865 is a publicly disclosed vulnerability and details have been made available in security advisories.