Tenda AC20 Telnet Service telnet websFormDefine command injection
38Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 14%
de la publicación al arma0 días
Publicada en NVD17 ago
1ª PoC17 ago
probabilidad de explotación
14%top 4% de las CVE
explotación observada
noninguna fuente lo reporta
3 exploit(s) público(s)
A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
Tenda · AC20PoCs públicas encontradas — 3
exploitdbwww.exploit-db.com/exploits/52418no verificadogithubgithub.com/byteReaper77/CVE-2025-9090★ 1cve_referencegithub.com/ZZ2266/.github.io/blob/main/AC20/telnet/readme.md#poc-exploit-stepsno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.