CVE-2025-45042: Command Injection
Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45042?
CVE-2025-45042 is classified as a high severity vulnerability due to its potential for command injection.
How do I fix CVE-2025-45042?
To mitigate CVE-2025-45042, disable the Telnet functionality on Tenda AC9 devices if not needed and update to the latest firmware.
What is the impact of CVE-2025-45042 on Tenda AC9 routers?
CVE-2025-45042 allows attackers to execute arbitrary commands on the device through the Telnet service, compromising the router's security.
Is CVE-2025-45042 specific to any firmware version?
CVE-2025-45042 affects Tenda AC9 routers running firmware version 15.03.05.14 and potentially other versions with the same Telnet vulnerability.
How was CVE-2025-45042 discovered?
CVE-2025-45042 was discovered through security research that identified vulnerabilities in the Telnet function of the Tenda AC9.