CVE-2026-6989: Tenda F453 Telnet Service telnet TendaTelnet command injection
A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6989?
CVE-2026-6989 is classified as a high severity vulnerability due to the potential for remote command injection.
How do I fix CVE-2026-6989?
To fix CVE-2026-6989, update the Tenda F453 firmware to version 1.0.0.4 or later.
What systems are affected by CVE-2026-6989?
CVE-2026-6989 affects Tenda F453 devices running firmware versions up to and including 1.0.0.3.
What type of attack is possible with CVE-2026-6989?
CVE-2026-6989 allows attackers to perform command injection via the Telnet service.
Is CVE-2026-6989 remotely exploitable?
Yes, CVE-2026-6989 is remotely exploitable, allowing an attacker to execute commands on the vulnerable device.