An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTenda Ac10
HWTendaall versionsTenda Ac10 Firmware
OSTenda≤ 15.03.06.23_cnTenda Ac7
HWTendaall versionsTenda Ac7 Firmware
OSTenda≤ 15.03.06.44_cnTenda Ac9
HWTendaall versionsTenda Ac9 Firmware
OSTenda≤ 15.03.05.19\(6318\)_cn
CISA KEV — detailsi
- Vendori
- Tenda
- Producti
- AC7, AC9, and AC10 Routers
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- May 3, 2022(overdue)
Apply updates per vendor instructions.
Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.
Related vulnerabilities
Stack buffer overflow w Tenda AC7 — RCE przez parametr wanSpeed
Stack buffer overflow w Tenda AC7 via parametr wanMTU
Stack buffer overflow w Tenda AC7 via parametr mac (/goform/AdvSetMacMtuWan)
Stack buffer overflow w Tenda AC7 — interfejs AdvSetMacMtuWan
Buffer overflow w Tenda AC10 – RCE i DoS przez pole serviceName