CVE-2025-57639: Tenda AC9 Firmware
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf function of the httpd file.
Affected products
- Tenda AC9 Firmware: version 1.0 only
Published 2025-09-23. Last modified 2026-06-17.