Metrics
Affected Vendors & Products
Wed, 16 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tenda
Tenda o3 Tenda o3 Firmware |
|
CPEs | cpe:2.3:h:tenda:o3:2.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:o3_firmware:1.0.0.12\(3880\):*:*:*:*:*:*:* |
|
Vendors & Products |
Tenda
Tenda o3 Tenda o3 Firmware |
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
Thu, 10 Jul 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the function fromTraceroutGet of the file /goform/getTraceroute of the component httpd. The manipulation of the argument dest leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
Title | Tenda O3V2 httpd getTraceroute fromTraceroutGet command injection | |
Weaknesses | CWE-74 CWE-77 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-07-10T21:02:07.027Z
Updated: 2025-07-11T16:58:46.182Z
Reserved: 2025-07-10T07:48:26.071Z
Link: CVE-2025-7415

Updated: 2025-07-11T16:58:42.922Z

Status : Analyzed
Published: 2025-07-10T21:15:30.443
Modified: 2025-07-16T15:00:33.120
Link: CVE-2025-7415

No data.