CVE-2025-44877: Tenda AC9 Firmware

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

Affected products

  • Tenda AC9 Firmware: version 15.03.06.42_multi only

Published 2025-05-02. Last modified 2026-06-17.