Tenda AC7 Command Injection Vulnerability in Telnet Function

Vulnerability

A critical command injection vulnerability has been identified in the Tenda AC7 1200M router, specifically in version 15.03.06.44. The issue arises in the 'TendaTelnet' function within the '/goform/telnet' file, where improper handling of the 'lan_ip' argument allows for operating system command injection. This vulnerability can be exploited remotely.

Impact

Successful exploitation allows for arbitrary command execution on the device's operating system.

Reproduction

To reproduce this vulnerability, send a request to the '/goform/telnet' endpoint with a crafted 'lan_ip' argument that includes malicious payloads designed to be executed as operating system commands. The injection point is the 'TendaTelnet' function, which processes the 'lan_ip' argument without proper validation or sanitization, allowing for command injection.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
8.1
remediation
0.0
relevance
0.0
threat
1.6
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.