Tenda · Tenda Ac10 · CVE-2023-37144
**Name of the Vulnerable Software and Affected Versions**
Tenda AC10 version 15.03.06.26
**Description**
The issue is related to a command injection vulnerability in the function formWriteFacMac, which can be exploited via the `mac` parameter. This vulnerability may allow a remote attacker to execute arbitrary commands.
**Recommendations**
For Tenda AC10 version 15.03.06.26, as a temporary workaround, consider restricting access to the `formWriteFacMac` function and the `mac` parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.