First published: Mon May 05 2025(Updated: )
Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda AC7/AC9/AC10 Routers | ||
All of | ||
Tenda AC9 | =15.03.05.14 | |
Tenda AC7/AC9/AC10 Routers | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-45042 is classified as a high severity vulnerability due to its potential for command injection.
To mitigate CVE-2025-45042, disable the Telnet functionality on Tenda AC9 devices if not needed and update to the latest firmware.
CVE-2025-45042 allows attackers to execute arbitrary commands on the device through the Telnet service, compromising the router's security.
CVE-2025-45042 affects Tenda AC9 routers running firmware version 15.03.05.14 and potentially other versions with the same Telnet vulnerability.
CVE-2025-45042 was discovered through security research that identified vulnerabilities in the Telnet function of the Tenda AC9.