Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-30902 | OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf function of the httpd file. |
Thu, 25 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda ac9 Firmware
|
|
| CPEs | cpe:2.3:h:tenda:ac9:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac9_firmware:1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda ac9 Firmware
|
Thu, 25 Sep 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda ac9 |
|
| Vendors & Products |
Tenda
Tenda ac9 |
Wed, 24 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-78 | |
| Metrics |
cvssV3_1
|
Tue, 23 Sep 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf function of the httpd file. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-24T18:36:02.906Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-57639
Updated: 2025-09-24T18:35:56.429Z
Status : Analyzed
Published: 2025-09-23T18:15:35.593
Modified: 2025-09-25T16:09:17.580
Link: CVE-2025-57639
No data.
OpenCVE Enrichment
Updated: 2025-09-25T08:22:12Z
EUVD