CVE-2025-0528
published 2025-01-17CVE-2025-0528: A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality…
PriorityP359high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
5.81%
92.3th percentile
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request Handler. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | ac10 | — | — |
| tenda | ac10_firmware | — | — |
| tenda | ac18 | — | — |
| tenda | ac18_firmware | — | — |
| tenda | ac8 | — | — |
| tenda | ac8_firmware | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.6HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.08.3HIGHAV:N/AC:L/Au:M/C:C/I:C/A:C
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jj49-w25f-3wxj: A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16
ghsa_unreviewed·2025-01-17
CVE-2025-0528 [HIGH] CWE-74 GHSA-jj49-w25f-3wxj: A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request Handler. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Red Hat
vllm: quen3: RCE in vllm tool call parser for qwen3coder
vendor_redhat·2025-08-20·CVSS 8.8
CVE-2025-9141 [HIGH] CWE-502 vllm: quen3: RCE in vllm tool call parser for qwen3coder
vllm: quen3: RCE in vllm tool call parser for qwen3coder
A vulnerability was found in vLLM's Qwen3 Coder tool parser. Since this parser uses Python's eval() function, it poses a risk of arbitrary code execution. This vulnerability appears during the parameter conversion process when the parser attempts to handle complex data types.
Statement: This vulnerability was discovered and fixed in the upstream qwen3 component. It never affected any Red Hat products.
The impact is Important as it could allow remote code execution. The precondition of an attacker needing valid login credentials, prevents it from being critical.
Package: rhelai1/deepseek-r1-0528-quantized-w4a16 (Red Hat Enterprise Linux AI (RHEL AI)) - Not affected
Package: rhelai1/gemma-3n-e4b-it (Red Hat Enterprise Linux AI (RHE
No detection rules found.
No public exploits indexed.
2025-01-17
Published