CVE-2025-7415: Tenda O3V2 httpd getTraceroute fromTraceroutGet command injection
A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the function fromTraceroutGet of the file /goform/getTraceroute of the component httpd. The manipulation of the argument dest leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7415?
CVE-2025-7415 is classified as a critical vulnerability.
What component of Tenda O3V2 is affected by CVE-2025-7415?
CVE-2025-7415 affects the httpd component, specifically the function fromTraceroutGet.
What type of vulnerability is CVE-2025-7415?
CVE-2025-7415 is a command injection vulnerability.
How can I mitigate CVE-2025-7415?
To mitigate CVE-2025-7415, it is recommended to update the Tenda O3V2 firmware to the latest version.
How does CVE-2025-7415 affect the Tenda O3V2 device?
CVE-2025-7415 allows an attacker to manipulate the dest argument, leading to potential command execution on the device.