HIGH
Tenda G1 Firmware Update check_upload_file data authenticity
Published Aug 14, 2025
7.5
HIGHCVSS 4.0
EPSS 0.35%
Description
A vulnerability has been found in Tenda G1 16.01.7.8(3660). Affected by this issue is the function check_upload_file of the component Firmware Update Handler. The manipulation leads to insufficient verification of data authenticity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
Affected products
-
- Version 16.01.7.8(3660)StatusaffectedConstraints-
- Version
AND
- 16.01.7.8\(3660\)
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-24945 Advisory
- https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/G1_Auth.md exploitpatchThird Party Advisory
- https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/G1_Inte.md patchThird Party Advisory
- https://vuldb.com/?ctiid.319976 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.319976 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.628605 third-party-advisoryThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.628606 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.tenda.com.cn/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-24945 | Advisory | |
| https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/G1_Auth.md | exploitpatchThird Party Advisory | |
| https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/G1_Inte.md | patchThird Party Advisory | |
| https://vuldb.com/?ctiid.319976 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.319976 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.628605 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.628606 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.tenda.com.cn/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 14, 2025
Updated Aug 14, 2025
Reserved Aug 13, 2025
Link CVE-2025-8980
CISA Vulnrichment
Updated Aug 14, 2025
ENISA EUVD
EUVD-2025-24945 Assigner VulDB
Published Aug 14, 2025
Updated Aug 14, 2025
Exploited since n/a
Link EUVD-2025-24945