Metrics
Affected Vendors & Products
Mon, 09 Jun 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda ac9 Tenda ac9 Firmware |
|
| CPEs | cpe:2.3:h:tenda:ac9:1.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac9_firmware:15.03.2.13:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda
Tenda ac9 Tenda ac9 Firmware |
Mon, 09 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 07 Jun 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The manipulation of the argument list leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Title | Tenda AC9 POST Request SetIPTVCfg formSetIptv command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-07T13:31:06.620Z
Updated: 2025-06-09T15:06:31.883Z
Reserved: 2025-06-06T20:11:59.450Z
Link: CVE-2025-5836
Updated: 2025-06-09T15:06:17.919Z
Status : Analyzed
Published: 2025-06-07T14:15:22.500
Modified: 2025-06-09T19:07:49.417
Link: CVE-2025-5836
No data.
ReportizFlow