CVE-2026-6989
גבוהה 8.8
תיאור (מקור, אנגלית)
A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
2.1 (LOW)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 3% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-74, CWE-77
מוצרים מושפעים
tenda: f453 firmware; tenda: f453
קישורים
- https://github.com/alc9700jmo/CVE/issues/24 ExploitIssue TrackingThird Party Advisory
- https://vuldb.com/submit/796560 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359541 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359541/cti Permissions RequiredVDB Entry
- https://www.tenda.com.cn/ Product