CVE-2018-14558

⚠ KEVEPSS 78.3%

Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability

Added to CISA KEV: 11/3/2021

Description

Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.

Affected packages (0)

No package mapping in OSV.