VulnerabilityAnalyzed
CVE-2025-9090
A vulnerability was identified in Tenda AC20 16.03.08.12.
LOW 2.1EPSS 14.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 14.11% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-77
- Affected
- tenda/ac20 firmware
- Source
- cna@vuldb.com
References
- https://github.com/ZZ2266/.github.io/blob/main/AC20/telnet/readme.mdExploit, Third Party Advisory
- https://github.com/ZZ2266/.github.io/blob/main/AC20/telnet/readme.md#poc-exploit-stepsExploit, Third Party Advisory
- https://vuldb.com/?ctiid.320358Permissions Required, VDB Entry
- https://vuldb.com/?id.320358Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.632232Third Party Advisory, VDB Entry
- https://www.tenda.com.cn/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.