PT-2020-4297 · Tenda · Tenda Ac15 Ac1900
CVE-2020-10987
·
Published
2020-07-13
·
Updated
2026-08-17
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda AC15 AC1900 version 15.03.05.19
Description
Remote attackers can execute arbitrary system commands due to insufficient neutralization of special elements passed in the URI. This is possible via the 'goform/setUsbUnload' endpoint using the
deviceName POST parameter. Real-world incidents have been observed where this issue was exploited to deliver a DDOSAgent.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
deviceName parameter in the 'goform/setUsbUnload' endpoint to minimize the risk of exploitation.Exploit
RCE
DoS
Special Elements Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda Ac15 Ac1900