Логотип exploitDog
bind:CVE-2025-46625
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-46625

Количество 3

Количество 3

nvd логотип

CVE-2025-46625

9 месяцев назад

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-q25g-m88j-xmgx

9 месяцев назад

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2025-05628

9 месяцев назад

Уязвимость функции setLanCfg() микропрограммного обеспечения маршрутизаторов Tenda RX2 Pro, позволяющая нарушителю выполнить произвольные команды

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-46625

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.

CVSS3: 8.8
1%
Низкий
9 месяцев назад
github логотип
GHSA-q25g-m88j-xmgx

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.

CVSS3: 8.8
1%
Низкий
9 месяцев назад
fstec логотип
BDU:2025-05628

Уязвимость функции setLanCfg() микропрограммного обеспечения маршрутизаторов Tenda RX2 Pro, позволяющая нарушителю выполнить произвольные команды

CVSS3: 8.8
1%
Низкий
9 месяцев назад

Уязвимостей на страницу