Description
A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request Handler. Executing manipulation of the argument ipaddress can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Problem types
Product status
Timeline
| 2025-12-23: | Advisory disclosed |
| 2025-12-23: | VulDB entry created |
| 2025-12-23: | VulDB entry last update |
Credits
z472421519 (VulDB User)
References
vuldb.com/?id.337853 (VDB-337853 | Tenda WH450 HTTP Request CheckTools command injection)
vuldb.com/?ctiid.337853 (VDB-337853 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.720885 (Submit #720885 | Tenda WH450 V1.0.0.18 Command Injection)
github.com/...n/PoC/CMD/Tenda_WH450/CheckTools/CheckTools.md
github.com/...n/PoC/CMD/Tenda_WH450/CheckTools/CheckTools.md
www.tenda.com.cn/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.