Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2fpj-h75c-c5vr

Опубликовано: 11 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 6.3

Описание

A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl5g.public.country can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl5g.public.country can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

EPSS

Процентиль: 86%
0.02891
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-77
CWE-78

Связанные уязвимости

CVSS3: 6.3
nvd
3 месяца назад

A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl5g.public.country can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

CVSS3: 8.8
fstec
3 месяца назад

Уязвимость функцию formWifiApScan() микропрограммного обеспечения маршрутизаторов Tenda AC6, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 86%
0.02891
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-77
CWE-78