PT-2020-4297 · Tenda · Tenda Ac15 Ac1900

CVE-2020-10987

·

Published

2020-07-13

·

Updated

2026-08-17

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda AC15 AC1900 version 15.03.05.19
Description Remote attackers can execute arbitrary system commands due to insufficient neutralization of special elements passed in the URI. This is possible via the 'goform/setUsbUnload' endpoint using the deviceName POST parameter. Real-world incidents have been observed where this issue was exploited to deliver a DDOSAgent.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the deviceName parameter in the 'goform/setUsbUnload' endpoint to minimize the risk of exploitation.

Exploit

RCE

DoS

Special Elements Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04790
CVE-2020-10987

Affected Products

Tenda Ac15 Ac1900