CRITICAL

CVE-2020-10987

Tenda Ac15 Firmware 2020-07-13 CVSS v3.1
CVSS
9.8
KEV

Description

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

Summary dbcve.org

The Tenda AC15 AC1900 router firmware version 15.03.05.19 contains a command injection vulnerability in the /goform/setUsbUnload web endpoint. The deviceName POST parameter is not properly sanitized before being passed to a system call, allowing an unauthenticated remote attacker to inject and execute arbitrary operating system commands with root privileges.

Mitigation

Apply the latest vendor firmware patch when available, or mitigate by restricting web interface access to trusted networks only and disabling USB sharing features if not required.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

79.81%
Probability of exploitation in next 30 days
99.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE