CVE-2025-8979: Tenda AC15 Firmware Update check_fw data authenticity
A vulnerability was identified in Tenda AC15 15.13.07.13. Affected by this vulnerability is the function checkfwtype/splitfireware/checkfw of the component Firmware Update Handler. The manipulation leads to insufficient verification of data authenticity. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8979?
CVE-2025-8979 is considered a high-severity vulnerability due to its potential for exploitation via insufficient verification of data authenticity.
How do I fix CVE-2025-8979?
To mitigate CVE-2025-8979, update the firmware of the Tenda AC15 router to the latest version that addresses this vulnerability.
What type of attack can be launched using CVE-2025-8979?
An attacker can launch a firmware update attack that exploits the insufficient verification of data authenticity in CVE-2025-8979.
Which devices are affected by CVE-2025-8979?
CVE-2025-8979 affects the Tenda AC15 router, particularly with the firmware version 15.13.07.13.
What component of Tenda AC15 does CVE-2025-8979 target?
CVE-2025-8979 targets the Firmware Update Handler, specifically the functions check_fw_type, split_fireware, and check_fw.