CVE-2026-25857

Severity CVSS v4.0:
HIGH
Type:
CWE-78 OS Command Injections
Publication date:
07/02/2026
Last modified:
07/02/2026

Description

Tenda G300-F router firmware versio 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetWanDiag). The implementation constructs a shell command that invokes curl and incorporates attacker-controlled input into the command line without adequate neutralization. As a result, a remote attacker with access to the affected management interface can inject additional shell syntax and execute arbitrary commands on the device with the privileges of the management process.