CVE-2025-15048
Last modified
CVE-2025-15048 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request Handler. EPSS estimates a 11.34% chance of exploitation in the next 30 days.
Description
A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request Handler. Executing a manipulation of the argument ipaddress can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Wh450 Firmware | 1.0.0.18 |
References
- https://github.com/z472421519/BinaryAudit/blob/main/PoC/CMD/Tenda_WH450/CheckTools/CheckTools.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.337853Permissions Required, VDB Entry
- https://vuldb.com/?id.337853Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.720885Third Party Advisory, VDB Entry
- https://www.tenda.com.cn/Product
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-15048?
How severe is CVE-2025-15048?
How do I fix CVE-2025-15048?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-15041The BackWPup – WordPress Backup & Restore Plugin plugin for …7.2
- CVE-2025-15043The The Events Calendar plugin for WordPress is vulnerable t…5.4
- CVE-2025-15044A vulnerability was detected in Tenda WH450 1.0.0.18. Impact…9.8
- CVE-2025-15045A flaw has been found in Tenda WH450 1.0.0.18. The affected …9.8
- CVE-2025-15046A vulnerability has been found in Tenda WH450 1.0.0.18. The …9.8
- CVE-2025-15047A vulnerability was found in Tenda WH450 1.0.0.18. This affe…9.8
- CVE-2025-15049A vulnerability was identified in code-projects Online Farm …9.8
- CVE-2025-1505The Advanced AJAX Product Filters plugin for WordPress is vu…6.1
- CVE-2025-15050A security vulnerability has been detected in code-projects …8.8
- CVE-2025-15051IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vul…5.4
- CVE-2025-15052A vulnerability was detected in code-projects Student Inform…5.4
- CVE-2025-15053A flaw has been found in code-projects Student Information S…7.3
Are you affected by CVE-2025-15048?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
