CVE-2020-10987criticalunder attackCWE-78

CVE-2020-10987

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 80%
from disclosure to weapon1928 days
Published on NVDJul 13
1st PoC+1928d
CISA KEV+478d
exploitation probability
80%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

A vulnerability in Tenda AC15 routers allows attackers to run harmful commands on the device by sending specially crafted requests. This is critical because an attacker can take complete control of your router without needing any special access.

Technical detail

The setUsbUnload endpoint in Tenda AC15 v15.03.05.19 is susceptible to OS command injection through the deviceName POST parameter, enabling unauthenticated remote code execution. The vulnerability stems from insufficient input validation, allowing attackers to inject shell metacharacters and execute arbitrary system commands with router privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.