CVE-2025-5606: Tenda AC18 SetIPTVCfg formSetIptv command injection
Published Jun 4, 2025
·Updated
A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the function formSetIptv of the file /goform/SetIPTVCfg. The manipulation of the argument list leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda Ac18
All of the following
Tenda Ac18 Firmware=15.03.05.05
Tenda Ac18
Event History
Jun 4, 2025
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness
Jan 12, 57458
Event
via FIRST·12:25 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-5606?
CVE-2025-5606 has been declared as critical severity.
2
How do I fix CVE-2025-5606?
To fix CVE-2025-5606, update your Tenda AC18 to the latest firmware version released by the vendor.
3
What does CVE-2025-5606 exploit?
CVE-2025-5606 exploits the command injection vulnerability in the function formSetIptv of the file /goform/SetIPTVCfg.
4
Can CVE-2025-5606 be exploited remotely?
Yes, the exploit for CVE-2025-5606 can be initiated remotely.
5
What devices are affected by CVE-2025-5606?
CVE-2025-5606 affects Tenda AC18 firmware version 15.03.05.05.