CRITICAL
CVE-2020-10987
CVSS
9.8
KEV
Description
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
Summary dbcve.org
The Tenda AC15 AC1900 router firmware version 15.03.05.19 contains a command injection vulnerability in the /goform/setUsbUnload web endpoint. The deviceName POST parameter is not properly sanitized before being passed to a system call, allowing an unauthenticated remote attacker to inject and execute arbitrary operating system commands with root privileges.
Mitigation
Apply the latest vendor firmware patch when available, or mitigate by restricting web interface access to trusted networks only and disabling USB sharing features if not required.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
79.81%
Probability of exploitation in next 30 days
99.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.