CVE-2020-10987
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
A vulnerability in Tenda AC15 routers allows attackers to run harmful commands on the device by sending specially crafted requests. This is critical because an attacker can take complete control of your router without needing any special access.
The setUsbUnload endpoint in Tenda AC15 v15.03.05.19 is susceptible to OS command injection through the deviceName POST parameter, enabling unauthenticated remote code execution. The vulnerability stems from insufficient input validation, allowing attackers to inject shell metacharacters and execute arbitrary system commands with router privileges.
The full analysis of this CVE is available in Portuguese →