CVE-2025-57639: Tenda AC9 Firmware

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf function of the httpd file.

Affected products

  • Tenda AC9 Firmware: version 1.0 only

Published 2025-09-23. Last modified 2026-06-17.