Executive brief
Tenda AC7, AC9, and AC10 routers are vulnerable to command injection via the 'formsetUsbUnload' function. The vulnerability occurs because the 'dosystemCmd' function processes untrusted input from crafted 'goform/setUsbUnload' requests, allowing for arbitrary OS command execution.
Affected products
- Tenda AC7 Firmware through V15.03.06.44_CN(AC7)
- Tenda AC9 Firmware through V15.03.05.19(6318)_CN(AC9)
- Tenda AC10 Firmware through V15.03.06.23_CN(AC10)
Timeline
- 2018-10-30: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog