Command Injection Vulnerability in Tenda F453 Router by Tenda
CVE-2026-6989
Key Information:
Badges
What is CVE-2026-6989?
A command injection vulnerability has been detected in the Tenda F453 router, specifically impacting the TendaTelnet function within the Telnet Service. This flaw allows an attacker to execute arbitrary commands remotely through the /goform/telnet endpoint, leading to potential unauthorized access and manipulation of the device. Given that the exploit has been publicly disclosed, it is critical for users to apply necessary patches and secure their devices to prevent exploitation of this vulnerability.
Affected Version(s)
F453 1.0.0.0
F453 1.0.0.1
F453 1.0.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved