CVE-2025-44877: Command Injection
Tenda AC9 V15.03.06.42multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44877?
CVE-2025-44877 has a high severity rating due to its potential for remote command execution.
How do I fix CVE-2025-44877?
To fix CVE-2025-44877, update the Tenda AC9 firmware to the latest version provided by the manufacturer.
What impact does CVE-2025-44877 have on my Tenda AC9 router?
CVE-2025-44877 allows attackers to execute arbitrary commands, compromising the security of the Tenda AC9 router.
Is CVE-2025-44877 exploitable remotely?
Yes, CVE-2025-44877 can be exploited remotely by sending a crafted request to the affected Tenda AC9 router.
What can attackers do using CVE-2025-44877?
Attackers can execute arbitrary commands on the router by exploiting CVE-2025-44877, potentially gaining control over the device.