Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9m2g-6p8r-vr3w

Опубликовано: 15 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 6.3

Описание

A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manipulation of the argument cmdinput causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manipulation of the argument cmdinput causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

EPSS

Процентиль: 74%
0.00809
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 6.3
nvd
5 месяцев назад

A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manipulation of the argument cmdinput causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

CVSS3: 6.3
fstec
5 месяцев назад

Уязвимость функции formexeCommand() (/goform/exeCommand) компонента cmdinput микропрограммного обеспечения маршрутизаторов Tenda AC9 и AС15, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 74%
0.00809
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-77