Tenda AC9 POST Request SetIPTVCfg formSetIptv command injection

CVE Details

Basic Information

Title Tenda AC9 POST Request SetIPTVCfg formSetIptv command injection
Type cve
Published 2025-06-07T13:31:06.620Z
Last Seen

Product Information

Vendor Tenda
Product AC9
Version 15.03.02.13

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A critical vulnerability in Tenda AC9 15.03.02.13 allows remote attackers to execute arbitrary commands via command injection in the formSetIptv function of the /goform/SetIPTVCfg component. This can be exploited remotely and has been publicly disclosed.
AI Severity High
Vendor Tenda
Product AC9
Affected Version 15.03.02.13

Affected Products

  • Tenda AC9 15.03.02.13

Additional Information

CVE List
CWE List CWE-77, CWE-74
Bulletin Family

Description

A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The manipulation of the argument list leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.