Metrics
Affected Vendors & Products
Mon, 09 Jun 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tenda
Tenda ac9 Tenda ac9 Firmware |
|
CPEs | cpe:2.3:h:tenda:ac9:1.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac9_firmware:15.03.2.13:*:*:*:*:*:*:* |
|
Vendors & Products |
Tenda
Tenda ac9 Tenda ac9 Firmware |
Mon, 09 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 07 Jun 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The manipulation of the argument list leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
Title | Tenda AC9 POST Request SetIPTVCfg formSetIptv command injection | |
Weaknesses | CWE-74 CWE-77 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-07T13:31:06.620Z
Updated: 2025-06-09T15:06:31.883Z
Reserved: 2025-06-06T20:11:59.450Z
Link: CVE-2025-5836

Updated: 2025-06-09T15:06:17.919Z

Status : Analyzed
Published: 2025-06-07T14:15:22.500
Modified: 2025-06-09T19:07:49.417
Link: CVE-2025-5836

No data.