← volver
CVE-2025-5836

Tenda AC9 POST Request SetIPTVCfg formSetIptv command injection

CVSS 5.3 MEDIUMEPSS 3.0%CWE-74CWE-77
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 3.0%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
07 jun 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The manipulation of the argument list leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
Tenda · AC9

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →