CVE-2025-44867

Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:w20e_firmware:15.11.0.6:*:*:*:*:*:*:*
cpe:2.3:h:tenda:w20e:-:*:*:*:*:*:*:*

History

27 May 2025, 16:31

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-01 18:15

Updated : 2025-05-27 16:31


NVD link : CVE-2025-44867

Mitre link : CVE-2025-44867

CVE.ORG link : CVE-2025-44867


JSON object : View

Products Affected

tenda

  • w20e_firmware
  • w20e
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')