Vulnerability Description
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request Handler. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ac8 Firmware | 16.03.10.20 |
| Tenda | Ac8 | - |
| Tenda | Ac10 Firmware | 16.03.10.20 |
| Tenda | Ac10 | - |
| Tenda | Ac18 Firmware | 16.03.10.20 |
| Tenda | Ac18 | - |
Related Weaknesses (CWE)
References
- https://github.com/Pr0b1em/IoT/blob/master/TendaAC10v16.03.10.20telnet.mdExploitThird Party Advisory
- https://vuldb.com/?ctiid.292412Permissions RequiredThird Party AdvisoryVDB Entry
- https://vuldb.com/?id.292412Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.478175Third Party AdvisoryVDB Entry
- https://www.tenda.com.cn/Product
- https://github.com/Pr0b1em/IoT/blob/master/TendaAC10v16.03.10.20telnet.mdExploitThird Party Advisory
FAQ
What is CVE-2025-0528?
CVE-2025-0528 is a vulnerability with a CVSS score of 7.2 (HIGH). A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the compon...
How severe is CVE-2025-0528?
CVE-2025-0528 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-0528?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ac8 Firmware, Tenda Ac8, Tenda Ac10 Firmware, Tenda Ac10, Tenda Ac18 Firmware.