Description
Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the doSystemCmd function, causing an arbitrary command execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-4496 | Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the doSystemCmd function, causing an arbitrary command execution. |
References
History
Mon, 17 Mar 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda ac10 Tenda ac10 Firmware |
|
| Weaknesses | CWE-77 | |
| CPEs | cpe:2.3:h:tenda:ac10:1.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac10_firmware:15.03.06.23:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda
Tenda ac10 Tenda ac10 Firmware |
Fri, 21 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Thu, 20 Feb 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the doSystemCmd function, causing an arbitrary command execution. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-21T17:30:19.069Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25675
Updated: 2025-02-21T17:30:12.805Z
Status : Analyzed
Published: 2025-02-20T23:15:12.870
Modified: 2025-03-17T14:26:22.483
Link: CVE-2025-25675
No data.
OpenCVE Enrichment
No data.
EUVD