PT-2025-49758 · Tenda · Tenda Ac9

Jiahui2888

·

Published

2025-12-09

·

Updated

2025-12-11

·

CVE-2025-14286

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tenda AC9 version 15.03.05.14 multi
Description A flaw exists in Tenda AC9 version 15.03.05.14 multi related to an unknown functionality within the /cgi-bin/DownloadCfg.jpg file of the Configuration File Handler component. This issue allows for information disclosure and can be exploited remotely. The exploit for this issue has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-14286

Affected Products

Tenda Ac9