CVE 5.3 MEDIUM

Tenda AC20 Telnet Service telnet websFormDefine command injection_CVE-2025-9090

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Basic Information

ID CVE-2025-9090
Source VulDB
Published Aug 17, 2025 at 02:02

Affected Product

Vendor Tenda
Product AC20
Version 16.03.08.12
Affected Versions Tenda AC20 16.03.08.12

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.