PT-2025-33408 · Tenda · Tenda G1

Iot_Res

·

Published

2025-08-14

·

Updated

2025-08-15

·

CVE-2025-8980

CVSS v2.0
6.8
VectorAV:N/AC:H/Au:M/C:C/I:C/A:C

Name of the Vulnerable Software and Affected Versions:

Tenda G1 version 16.01.7.8(3660)

Description:

A vulnerability exists in the Tenda G1 device due to insufficient verification of data authenticity within the Firmware Update Handler component. The `check upload file` function is affected, allowing for potential remote code execution. Exploitation is considered difficult, but the exploit has been publicly disclosed.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2025-8980

Affected Products

Tenda G1