An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of the account module in the goform/setmodules route.
| Software | From | Fixed in |
|---|---|---|
| tenda / w18e_firmware | 16.01.0.11(2044) | 16.01.0.11(2044).x |