Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29169 | A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manipulation of the argument cmdinput causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. |
Fri, 19 Sep 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda ac15 Firmware
Tenda ac9 Firmware |
|
| CPEs | cpe:2.3:h:tenda:ac15:-:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac9:1.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac15_firmware:15.03.05.14:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac9_firmware:15.03.05.14:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda ac15 Firmware
Tenda ac9 Firmware |
Wed, 17 Sep 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda ac15 Tenda ac9 |
|
| Vendors & Products |
Tenda
Tenda ac15 Tenda ac9 |
Mon, 15 Sep 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Sep 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manipulation of the argument cmdinput causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |
| Title | Tenda AC9/AC15 exeCommand formexeCommand os command injection | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-15T11:59:00.751Z
Reserved: 2025-09-14T15:40:13.804Z
Link: CVE-2025-10442
Updated: 2025-09-15T11:58:53.346Z
Status : Analyzed
Published: 2025-09-15T11:15:33.970
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-10442
No data.
OpenCVE Enrichment
Updated: 2025-09-17T10:08:34Z
EUVD