Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-49r7-qrrc-gw83

Опубликовано: 11 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2
CVSS3: 4.7

Описание

A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

EPSS

Процентиль: 91%
0.04554
Низкий

2 Low

CVSS4

4.7 Medium

CVSS3

Дефекты

CWE-77
CWE-787

Связанные уязвимости

CVSS3: 4.7
nvd
3 месяца назад

A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 4.7
fstec
3 месяца назад

Уязвимость функцию fromSetWirelessRepeat() микропрограммного обеспечения маршрутизаторов Tenda AC10U, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 91%
0.04554
Низкий

2 Low

CVSS4

4.7 Medium

CVSS3

Дефекты

CWE-77
CWE-787