CVE 5.3 MEDIUM

Tenda AC7 AdvSetLanip command injection_CVE-2025-11523

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was detected in Tenda AC7 15.03.06.44. This vulnerability affects unknown code of the file /goform/AdvSetLanip. The manipulation of the argument lanIp results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

Basic Information

ID CVE-2025-11523
Source VulDB
Published Oct 9, 2025 at 01:02

Affected Product

Vendor Tenda
Product AC7
Version 15.03.06.44
Affected Versions Tenda AC7 15.03.06.44

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.