CVE Details
Basic Information
| Title | Tenda O3V2 httpd setPingInfo fromNetToolGet os command injection |
|---|---|
| Type | cve |
| Published | 2025-07-10T20:32:07.344Z |
| Modified | 2025-07-10T20:47:41.403Z |
Product Information
| Vendor | Tenda |
|---|---|
| Product | O3V2 |
| Version | 1.0.0.12(3880) |
CVSS Information
| Base Score | 5.3 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
AI Analysis
| AI Description | A critical vulnerability in the Tenda O3V2 router allows remote attackers to inject OS commands via the setPingInfo function, potentially leading to full system control. |
|---|---|
| AI Severity | Critical |
| AI Vendor | Tenda |
| AI Product | Tenda O3V2 |
| AI Version | 1.0.0.12(3880) |
Affected Products
- Tenda O3V2 1.0.0.12(3880)
Additional Information
| CWE List | CWE-78, CWE-77 |
|---|---|
| Source | VulDB |
Description
A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function fromNetToolGet of the file /goform/setPingInfo of the component httpd. The manipulation of the argument domain leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.