Tenda CP3 apollo sub_F3C8C command injection

CVE Details

Basic Information

Title Tenda CP3 apollo sub_F3C8C command injection
Type cve
Published 2025-06-06T12:00:23.470Z
Last Seen

Product Information

Vendor Tenda
Product CP3
Version 11.10.00.2311090948

CVSS Information

Base Score 5.1 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A command injection vulnerability in the apollo module’s sub_F3C8C function of Tenda CP3 version 11.10.00.2311090948 allows remote attackers to execute arbitrary commands, leading to potential system compromise.
AI Severity Critical
Vendor Tenda
Product CP3
Affected Version 11.10.00.2311090948

Affected Products

  • Tenda CP3 11.10.00.2311090948

Additional Information

CVE List
CWE List CWE-77, CWE-74
Bulletin Family

Description

A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical. Affected by this vulnerability is the function sub_F3C8C of the file apollo. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.