PT-2018-3769 · Tenda · Tenda Ac9+2

Published

2018-07-21

·

Updated

2025-03-20

·

CVE-2018-14558

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC7 versions through V15.03.06.44 CN(AC7) Tenda AC9 versions through V15.03.05.19(6318) CN(AC9) Tenda AC10 versions through V15.03.06.23 CN(AC10)
Description A command injection issue allows attackers to execute arbitrary OS commands via a crafted "goform/setUsbUnload" request. This occurs because the formsetUsbUnload function executes a dosomeCmd function with untrusted input. The vulnerability exists due to the lack of neutralization of special elements used in the operating system command.
Recommendations For Tenda AC7 versions through V15.03.06.44 CN(AC7), consider disabling the formsetUsbUnload function until a patch is available. For Tenda AC9 versions through V15.03.05.19(6318) CN(AC9), restrict access to the "goform/setUsbUnload" request to minimize the risk of exploitation. For Tenda AC10 versions through V15.03.06.23 CN(AC10), avoid using the dosomeCmd function with untrusted input until the issue is resolved. As a temporary workaround, consider restricting the use of the formsetUsbUnload function in all affected devices until a patch is available.

Exploit

Fix

DoS

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05955
CVE-2018-14558

Affected Products

Tenda Ac10
Tenda Ac7
Tenda Ac9