Total vulnerabilities in the database
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.
Software | From | Fixed in |
---|---|---|
tenda / ac9_firmware | 15.03.05.19(6318)_cn | 15.03.05.19(6318)_cn.x |
tenda / ac15_firmware | 15.03.05.19_cn | 15.03.05.19_cn.x |
tenda / ac18_firmware | 15.03.05.19(6318)_cn | 15.03.05.19(6318)_cn.x |