CVE-2025-14286

A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/DownloadCfg.jpg of the component Configuration File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
References
Link Resource
https://github.com/Madgeaaaaa/MY_VULN_2/blob/main/Tenda/VULN11.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.334874 Permissions Required VDB Entry
https://vuldb.com/?id.334874 Third Party Advisory VDB Entry
https://vuldb.com/?submit.702723 Third Party Advisory VDB Entry
https://www.tenda.com.cn/ Product
https://github.com/Madgeaaaaa/MY_VULN_2/blob/main/Tenda/VULN11.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac9_firmware:15.03.05.14_multi:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac9_firmware:1.0:*:*:*:*:*:*:*

History

11 Dec 2025, 17:15

Type Values Removed Values Added
References () https://github.com/Madgeaaaaa/MY_VULN_2/blob/main/Tenda/VULN11.md - () https://github.com/Madgeaaaaa/MY_VULN_2/blob/main/Tenda/VULN11.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.334874 - () https://vuldb.com/?ctiid.334874 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.334874 - () https://vuldb.com/?id.334874 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.702723 - () https://vuldb.com/?submit.702723 - Third Party Advisory, VDB Entry
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product
First Time Tenda
Tenda ac9 Firmware
CPE cpe:2.3:o:tenda:ac9_firmware:15.03.05.14_multi:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac9_firmware:1.0:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo

09 Dec 2025, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-09 16:17

Updated : 2025-12-11 17:15


NVD link : CVE-2025-14286

Mitre link : CVE-2025-14286

CVE.ORG link : CVE-2025-14286


JSON object : View

Products Affected

tenda

  • ac9_firmware
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control

NVD-CWE-noinfo