CVE-2024-48825: Tenda AC7 Firmware

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.

Affected products

  • Tenda AC7 Firmware: version 15.03.06.44 only

Published 2024-10-28. Last modified 2026-06-17.