CVE-2025-9090: Tenda AC20 Telnet Service telnet websFormDefine command injection
A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9090?
CVE-2025-9090 is considered a high-severity vulnerability due to its potential for remote command injection.
How do I fix CVE-2025-9090?
To fix CVE-2025-9090, update the Tenda AC20 to the latest firmware version provided by the manufacturer.
What component is affected by CVE-2025-9090?
CVE-2025-9090 affects the Telnet Service in the function websFormDefine of the file /goform/telnet.
Can CVE-2025-9090 be exploited remotely?
Yes, CVE-2025-9090 can be exploited remotely, allowing attackers to perform command injection.
Which device models are impacted by CVE-2025-9090?
CVE-2025-9090 impacts the Tenda AC20 router running firmware version 16.03.08.12.