AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-25857

HIGH · CVSS 8.8 EPSS 2.82%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-02-07 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It may be remotely exploitable.

CVE
CVE-2026-25857
Severity
HIGH
CVSS
8.8
EPSS
2.82%

Original NVD Description

Tenda G300-F router firmware version 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetWanDiag). The implementation constructs a shell command that invokes curl and incorporates attacker-controlled input into the command line without adequate neutralization. As a result, a remote attacker with access to the affected management interface can inject additional shell syntax and execute arbitrary commands on the device with the privileges of the management process.

Related CVEs

Other vulnerabilities affecting the same vendor(s)