PT-2025-33408 · Tenda · Tenda G1

Iot_Res

·

Published

2025-05-22

·

Updated

2025-08-15

·

CVE-2025-8980

CVSS v2.0

7.1

High

VectorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Tenda G1 version 16.01.7.8(3660)
Description: A vulnerability exists in the Tenda G1 device due to insufficient verification of data authenticity within the Firmware Update Handler component. The check upload file function is affected, allowing for potential remote code execution. Exploitation is considered difficult, but the exploit has been publicly disclosed.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

BDU:2025-10978
CVE-2025-8980

Affected Products

Tenda G1