6.8
CVE-2025-8980
- EPSS 0.31%
- Veröffentlicht 14.08.2025 19:32:10
- Zuletzt bearbeitet 18.08.2025 15:04:02
- Quelle cna@vuldb.com
- CVE-Watchlists
- Unerledigt
Tenda G1 Firmware Update check_upload_file data authenticity
A vulnerability has been found in Tenda G1 16.01.7.8(3660). Affected by this issue is the function check_upload_file of the component Firmware Update Handler. The manipulation leads to insufficient verification of data authenticity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tenda ≫ G1 Firmware Version16.01.7.8(3660)
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.229 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@vuldb.com | 6.6 | 0.7 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| cna@vuldb.com | 6.6 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| cna@vuldb.com | 6.8 | 3.2 | 10 |
AV:N/AC:H/Au:M/C:C/I:C/A:C
|
CWE-345 Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
https://www.tenda.com.cn/
https://vuldb.com/?id.319976
https://vuldb.com/?ctiid.319976
https://vuldb.com/?submit.628605
https://vuldb.com/?submit.628606
https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/G1_Inte.md
https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/G1_Auth.md