Skip to main content
HIGH

CVE-2026-25857

Tenda G300-F Command Injection via formSetWanDiag

CVSS v3

8.8

HIGH

EPSS Score

2.9 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

Tenda G300-F router firmware version 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetWanDiag). The implementation constructs a shell command that invokes curl and incorporates attacker-controlled input into the command line without adequate neutralization. As a result, a remote attacker with access to the affected management interface can inject additional shell syntax and execute arbitrary commands on the device with the privileges

Technical details

Published
2026-02-07
Last Modified
2026-03-05

Frequently asked questions

What is CVE-2026-25857?

Tenda G300-F router firmware version 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetWanDiag). The implementation constructs a shell command that invokes curl and incorporates attacker-controlled input into the command line without adequate neutralization. As a result, a remote attacker with access to the affected management interface can inject additional shell syntax and execute arbitrary commands on the device with the privileges

Is CVE-2026-25857 actively exploited?

A proof-of-concept exploit exists for CVE-2026-25857, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2026-25857?

CVE-2026-25857 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2026-25857 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key