A vulnerability has been found in Tenda G1 16.01.7.8(3660). Affected by this issue is the function check_upload_file of the component Firmware Update Handler. The manipulation leads to insufficient verification of data authenticity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/G1_Auth.md | Third Party Advisory |
https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/G1_Inte.md | Third Party Advisory |
https://vuldb.com/?ctiid.319976 | Permissions Required |
https://vuldb.com/?id.319976 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.628605 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.628606 | Third Party Advisory VDB Entry |
https://www.tenda.com.cn/ | Product |
Configurations
Configuration 1 (hide)
AND |
|
History
18 Aug 2025, 15:04
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
First Time |
Tenda g1 Firmware
Tenda Tenda g1 |
|
References | () https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/G1_Auth.md - Third Party Advisory | |
References | () https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/G1_Inte.md - Third Party Advisory | |
References | () https://vuldb.com/?ctiid.319976 - Permissions Required | |
References | () https://vuldb.com/?id.319976 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.628605 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.628606 - Third Party Advisory, VDB Entry | |
References | () https://www.tenda.com.cn/ - Product | |
CPE | cpe:2.3:h:tenda:g1:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:g1_firmware:16.01.7.8\(3660\):*:*:*:*:*:*:* |
14 Aug 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-14 20:15
Updated : 2025-08-18 15:04
NVD link : CVE-2025-8980
Mitre link : CVE-2025-8980
CVE.ORG link : CVE-2025-8980
JSON object : View
Products Affected
tenda
- g1_firmware
- g1
CWE
CWE-345
Insufficient Verification of Data Authenticity