CVE-2025-7415 | Tenda O3V2 1.0.0.12(3880) httpd /goform/getTraceroute fromTraceroutGet dest command injection
A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the function fromTraceroutGet of the file /goform/getTraceroute of the component httpd. The manipulation of the argument dest leads to command injection.
The identification of this vulnerability is CVE-2025-7415. The attack may be initiated remotely. Furthermore, there is an exploit available.