PT-2022-8821 · Tenda · Tenda Ac9

Li Yuan Cheng

·

Published

2022-02-11

·

Updated

2022-02-22

·

CVE-2020-26728

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC9 version V15.03.06.42 multi Tenda AC9 version V15.03.05.19(6318) CN
Description A vulnerability was discovered that allows for remote code execution via shell metacharacters in the guestuser field to the fastcall function with a POST request to the API endpoint.
Recommendations For Tenda AC9 version V15.03.06.42 multi, consider disabling the fastcall function until a patch is available. For Tenda AC9 version V15.03.05.19(6318) CN, avoid using the guestuser field in the affected API endpoint until the issue is resolved. As a temporary workaround, restrict access to the vulnerable module to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-26728

Affected Products

Tenda Ac9