Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-0528


A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request Handler. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.


Published

2025-01-17T15:15:12.430

Last Modified

2025-05-28T14:42:21.953

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:M/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: MULTIPLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

6.4

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-74
    CWE-77
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tenda ac8_firmware 16.03.10.20 Yes
Hardware tenda ac8 - No
Operating System tenda ac10_firmware 16.03.10.20 Yes
Hardware tenda ac10 - No
Operating System tenda ac18_firmware 16.03.10.20 Yes
Hardware tenda ac18 - No

References