Impact
The vulnerability exists in the CAte::HandleCmd function of the Kylin component of Tenda's ATE Module. By manipulating input to this function, an attacker can inject and execute arbitrary shell commands on the device. The flaw is based on improper command handling and lack of input validation, resulting in a command injection weakness. The impact includes confidentiality breach, integrity compromise, and potential availability disruptions if the attacker runs destructive commands.
Affected Systems
Devices affected are the Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C, and TC3T15C models. Firmware versions up to and including 20260625 are vulnerable. No specific version numbers beyond this date are known to be affected, so all prior to the update are at risk.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity vulnerability. EPSS Score: 2%, which indicates a low but non-zero exploitation probability, but the vulnerability is reachable remotely, making it attractive for attackers. The vulnerability is not listed in the CISA KEV catalog, but the low exploitation probability does not mitigate the risk of exploitation by a determined adversary. Handling the exposed command interface without proper validation enables attackers to execute arbitrary commands on the device.
OpenCVE Enrichment