216.73.217.22

CVE-2025-7414

· Published 10/07/2025 23:15 · Modified 29/04/2026 05:57 · Author: The MITRE Corporation

Labels: CVE-2025-7414

Essential information

Published
10/07/2025 23:15
Modified
29/04/2026 05:57
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
6.5 (v2) 8.8 HIGH (v3.1) 5.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CWE-77
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function fromNetToolGet of the file /goform/setPingInfo of the component httpd. The manipulation of the argument domain leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD status

NVD
View on NVD