CVE-2018-14558
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 9% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-78
מוצרים מושפעים
tenda: ac7 firmware; tenda: ac7; tenda: ac9 firmware; tenda: ac9; tenda: ac10 firmware; tenda: ac10
קישורים
- https://github.com/zsjevilhex/iot/blob/master/route/tenda/tenda-01/Tenda.md Broken LinkExploitThird Party Advisory
- https://github.com/zsjevilhex/iot/blob/master/route/tenda/tenda-01/Tenda.md Broken LinkExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource