CVE-2025-14286: Tenda AC9 Firmware

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/DownloadCfg.jpg of the component Configuration File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Affected products

  • Tenda AC9 Firmware: version 15.03.05.14_multi only

Published 2025-12-09. Last modified 2026-10-07.