---
id: CVE-2025-14286
title: A vulnerability was determined in Tenda AC9 15.03.05.14_multi
summary: >-
  A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by
  this vulnerability is an unknown functionality of the file
  /cgi-bin/DownloadCfg.jpg of the component Configuration File Handler. This
  manipulation causes informat…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
  - CWE-284
vendor: tenda
product: ac9_firmware
affected:
  - ac9_firmware = 15.03.05.14_multi
published: '2025-12-09'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14286'
references:
  - url: 'https://github.com/Madgeaaaaa/MY_VULN_2/blob/main/Tenda/VULN11.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.334874'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.334874'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.702723'
    label: cna@vuldb.com
  - url: 'https://www.tenda.com.cn/'
    label: cna@vuldb.com
  - url: 'https://github.com/Madgeaaaaa/MY_VULN_2/blob/main/Tenda/VULN11.md'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00675
epssPercentile: 0.50562
ingestedAt: '2026-10-07T20:46:46.786Z'
---

## Overview

A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/DownloadCfg.jpg of the component Configuration File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

## Affected

- `ac9_firmware = 15.03.05.14_multi`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
