6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request Handler. Executing manipulation of the argument ipaddress can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Basic Information
ID
CVE-2025-15048
Source
VulDB
Published
Dec 23, 2025 at 22:32
Affected Product
Vendor
Tenda
Product
WH450
Version
1.0.0.18
Affected Versions
Tenda WH450 1.0.0.18