CVE-2025-44867
published 2025-05-01CVE-2025-44867: Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This…
PriorityP346medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
1.11%
64.0th percentile
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | w20e_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code.
ghsa_unreviewed·2026-08-17·CVSS 6.3
CVE-2026-67967 [MEDIUM] CWE-121 Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code.
Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819
GHSA
GHSA-47r6-rvxr-w4cc: Tenda W20E V15
ghsa_unreviewed·2025-05-02
CVE-2025-44867 [MEDIUM] CWE-77 GHSA-47r6-rvxr-w4cc: Tenda W20E V15
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-01
Published