Total vulnerabilities in the database
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST request is used directly in a doSystemCmd call, causing OS command injection.
Software | From | Fixed in |
---|---|---|
tendacn / ac10_firmware | - | 15.03.06.23.x |
tendacn / ac9_firmware | 15.03.05.19 | 15.03.05.19.x |