5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was detected in Tenda AC7 15.03.06.44. This vulnerability affects unknown code of the file /goform/AdvSetLanip. The manipulation of the argument lanIp results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
Basic Information
ID
CVE-2025-11523
Source
VulDB
Published
Oct 9, 2025 at 01:02
Affected Product
Vendor
Tenda
Product
AC7
Version
15.03.06.44
Affected Versions
Tenda AC7 15.03.06.44