Remote Code Execution in Tenda FH451 Router by Shenzhen Jixiang Tenda Technology
CVE-2025-44176

6.5MEDIUM

What is CVE-2025-44176?

The Tenda FH451 router, specifically version V1.0.0.9, is susceptible to a vulnerability that allows attackers to execute arbitrary commands remotely. This issue arises in the formSafeEmailFilter function, which fails to properly validate input data, allowing malicious actors to inject and execute their own code. This vulnerability poses a significant risk, potentially compromising the security of the entire network connected to the affected device. Users are advised to secure their devices and apply necessary patches as soon as they become available.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-44176 : Remote Code Execution in Tenda FH451 Router by Shenzhen Jixiang Tenda Technology