Vulnerability Description
A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The manipulation of the argument list leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ac9 Firmware | 15.03.2.13 |
| Tenda | Ac9 | 1.0 |
Related Weaknesses (CWE)
References
- https://candle-throne-f75.notion.site/Tenda-AC9-formSetIptv-209df0aa11858061ae2bExploitThird Party Advisory
- https://vuldb.com/?ctiid.311579Permissions Required
- https://vuldb.com/?id.311579Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.591363Third Party AdvisoryVDB Entry
- https://www.tenda.com.cn/Product
- https://candle-throne-f75.notion.site/Tenda-AC9-formSetIptv-209df0aa11858061ae2bExploitThird Party Advisory
FAQ
What is CVE-2025-5836?
CVE-2025-5836 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The...
How severe is CVE-2025-5836?
CVE-2025-5836 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-5836?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ac9 Firmware, Tenda Ac9.