A vulnerability was identified in Tenda AC15 15.13.07.13. Affected by this vulnerability is the function check_fw_type/split_fireware/check_fw of the component Firmware Update Handler. The manipulation leads to insufficient verification of data authenticity. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/AC15_Auth.md | Exploit Third Party Advisory |
https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/AC15_Inte.md | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.319975 | Permissions Required |
https://vuldb.com/?id.319975 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.628602 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.628603 | Not Applicable |
https://www.tenda.com.cn/ | Product |
Configurations
Configuration 1 (hide)
AND |
|
History
18 Aug 2025, 15:03
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/AC15_Auth.md - Exploit, Third Party Advisory | |
References | () https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/AC15_Inte.md - Exploit, Third Party Advisory | |
References | () https://vuldb.com/?ctiid.319975 - Permissions Required | |
References | () https://vuldb.com/?id.319975 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.628602 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.628603 - Not Applicable | |
References | () https://www.tenda.com.cn/ - Product | |
First Time |
Tenda ac15
Tenda ac15 Firmware Tenda |
|
CPE | cpe:2.3:h:tenda:ac15:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac15_firmware:15.13.07.13:*:*:*:*:*:*:* |
14 Aug 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-14 20:15
Updated : 2025-08-18 15:03
NVD link : CVE-2025-8979
Mitre link : CVE-2025-8979
CVE.ORG link : CVE-2025-8979
JSON object : View
Products Affected
tenda
- ac15
- ac15_firmware
CWE
CWE-345
Insufficient Verification of Data Authenticity