Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j8cg-gpgg-pxf5

Опубликовано: 19 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.03.06.49_multi via the setUsbUnload functionality. The vulnerability is caused because the client controlled "deviceName" value is passed directly to the "doSystemCmd" function.

A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.03.06.49_multi via the setUsbUnload functionality. The vulnerability is caused because the client controlled "deviceName" value is passed directly to the "doSystemCmd" function.

EPSS

Процентиль: 94%
0.11787
Средний

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.03.06.49_multi via the setUsbUnload functionality. The vulnerability is caused because the client controlled "deviceName" value is passed directly to the "doSystemCmd" function.

EPSS

Процентиль: 94%
0.11787
Средний

Дефекты

CWE-77