CVE-2025-9090
published 2025-08-17CVE-2025-9090: A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service…
PriorityP181critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
14.11%
96.2th percentile
A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | ac20 | — | — |
| tenda | ac20_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for POST requests targeting /goform/telnet on Tenda AC20 devices; this endpoint is the injection point for CVE-2025-9090 command injection. ↗
- →After successful exploitation, the attacker checks for an open Telnet service on ports 23 and 2323; alert on unexpected Telnet connections originating from Tenda AC20 devices on these ports. ↗
- →The exploit uses a time-based (sleep) technique to confirm injection; detect anomalous response delays on POST requests to /goform/telnet as a blind command injection indicator. ↗
- →The exploit forks a child process to launch an interactive Telnet session after injection; monitor for unexpected child processes spawned from the web server process on the device. ↗
- ·The vulnerability is specific to Tenda AC20 firmware version 16.03.08.12; other firmware versions may or may not be affected. ↗
- ·The exploit is publicly disclosed and remotely exploitable without physical access; internet-exposed Tenda AC20 admin interfaces are at immediate risk. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
2025-08-17
Published