Executive brief
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 routers contains an OS command injection vulnerability. Remote attackers can execute arbitrary system commands via the deviceName POST parameter.
Affected products
- Tenda AC15 AC1900 15.03.05.19
Timeline
- 2020-07-13: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog