CVE Details
Basic Information
| Title | Tenda AC9 POST Request SetIPTVCfg formSetIptv command injection |
|---|---|
| Type | cve |
| Published | 2025-06-07T13:31:06.620Z |
| Last Seen |
Product Information
| Vendor | Tenda |
|---|---|
| Product | AC9 |
| Version | 15.03.02.13 |
CVSS Information
| Base Score | 5.3 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A critical vulnerability in Tenda AC9 15.03.02.13 allows remote attackers to execute arbitrary commands via command injection in the formSetIptv function of the /goform/SetIPTVCfg component. This can be exploited remotely and has been publicly disclosed. |
|---|---|
| AI Severity | High |
| Vendor | Tenda |
| Product | AC9 |
| Affected Version | 15.03.02.13 |
Affected Products
- Tenda AC9 15.03.02.13
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-77, CWE-74 |
| Bulletin Family |
References
Description
A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The manipulation of the argument list leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.