HIGH
Tenda AC15 Firmware Update check_fw data authenticity
Published Aug 14, 2025
7.5
HIGHCVSS 4.0
EPSS 0.42%
Description
A vulnerability was identified in Tenda AC15 15.13.07.13. Affected by this vulnerability is the function check_fw_type/split_fireware/check_fw of the component Firmware Update Handler. The manipulation leads to insufficient verification of data authenticity. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
Affected products
-
- Version 15.13.07.13StatusaffectedConstraints-
- Version
AND
- 15.13.07.13
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-24943 Advisory
- https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/AC15_Auth.md patchExploitThird Party Advisory
- https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/AC15_Inte.md exploitpatchThird Party Advisory
- https://vuldb.com/?ctiid.319975 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.319975 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.628602 third-party-advisoryThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.628603 third-party-advisoryNot Applicable
- https://www.tenda.com.cn/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-24943 | Advisory | |
| https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/AC15_Auth.md | patchExploitThird Party Advisory | |
| https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/AC15_Inte.md | exploitpatchThird Party Advisory | |
| https://vuldb.com/?ctiid.319975 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.319975 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.628602 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.628603 | third-party-advisoryNot Applicable | |
| https://www.tenda.com.cn/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 14, 2025
Updated Aug 14, 2025
Reserved Aug 13, 2025
Link CVE-2025-8979
CISA Vulnrichment
Updated Aug 14, 2025
ENISA EUVD
EUVD-2025-24943 Assigner VulDB
Published Aug 14, 2025
Updated Aug 14, 2025
Exploited since n/a
Link EUVD-2025-24943