A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manipulation of the argument cmdinput causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
References
Configurations
No configuration.
History
15 Sep 2025, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-15 11:15
Updated : 2025-09-15 15:21
NVD link : CVE-2025-10442
Mitre link : CVE-2025-10442
CVE.ORG link : CVE-2025-10442
JSON object : View
Products Affected
No product.