← back
CVE-2025-8979

Tenda AC15 Firmware Update check_fw data authenticity

CVSS 7.5 HIGHEPSS 0.4%CWE-345
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
14 Aug 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability was identified in Tenda AC15 15.13.07.13. Affected by this vulnerability is the function check_fw_type/split_fireware/check_fw of the component Firmware Update Handler. The manipulation leads to insufficient verification of data authenticity. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Affected products
Tenda · AC15

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →