Tenda WH450 Command Injection Vulnerability in HTTP Request Handler

Vulnerability

A command injection vulnerability has been identified in the Tenda WH450 router, specifically in the firmware version 1.0.0.18. The issue arises within the HTTP request handler for the '/goform/CheckTools' endpoint. This vulnerability can be exploited remotely by unauthenticated attackers, allowing them to execute arbitrary commands on the router. The exploitation involves manipulating the 'ipaddress' parameter with excessive data lengths, which triggers the command injection.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected router.

Reproduction

To reproduce this vulnerability, send a GET request to the '/goform/CheckTools' endpoint with the 'ipaddress' parameter. Include a payload that appends a command to be executed, such as a command to read the '/etc/passwd' file and write it to a temporary location.

Added: Dec 23, 2025, 11:25 PM
Updated: Dec 23, 2025, 11:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
1.5
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.