Junglewise Threat Intelligence

CVE-2018-14558: Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability

CVE-2018-14558 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Tenda Ac7, Tenda Ac9 Firmware, Tenda Ac9, Tenda AC10 firmware. Vendors: Tenda.

Executive brief

Tenda AC7, AC9, and AC10 routers are vulnerable to command injection via the 'formsetUsbUnload' function. The vulnerability occurs because the 'dosystemCmd' function processes untrusted input from crafted 'goform/setUsbUnload' requests, allowing for arbitrary OS command execution.

Affected products

  • Tenda AC7 Firmware through V15.03.06.44_CN(AC7)
  • Tenda AC9 Firmware through V15.03.05.19(6318)_CN(AC9)
  • Tenda AC10 Firmware through V15.03.06.23_CN(AC10)

Timeline

  • 2018-10-30: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats