A vulnerability was detected in Tenda AC7 15.03.06.44. This vulnerability affects unknown code of the file /goform/AdvSetLanip. The manipulation of the argument lanIp results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
2025-10-09T02:15:41.403
2025-10-09T22:17:03.017
Analyzed
CVSSv3.1: 6.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | tenda | ac7_firmware | 15.03.06.44 | Yes |
| Hardware | tenda | ac7 | 1.0 | No |