Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m35g-p77j-hqrh

Опубликовано: 08 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.8

Описание

Tenda G300-F router firmware versio 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetWanDiag). The implementation constructs a shell command that invokes curl and incorporates attacker-controlled input into the command line without adequate neutralization. As a result, a remote attacker with access to the affected management interface can inject additional shell syntax and execute arbitrary commands on the device with the privileges of the management process.

Tenda G300-F router firmware versio 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetWanDiag). The implementation constructs a shell command that invokes curl and incorporates attacker-controlled input into the command line without adequate neutralization. As a result, a remote attacker with access to the affected management interface can inject additional shell syntax and execute arbitrary commands on the device with the privileges of the management process.

EPSS

Процентиль: 57%
0.00338
Низкий

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

Tenda G300-F router firmware version 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetWanDiag). The implementation constructs a shell command that invokes curl and incorporates attacker-controlled input into the command line without adequate neutralization. As a result, a remote attacker with access to the affected management interface can inject additional shell syntax and execute arbitrary commands on the device with the privileges of the management process.

CVSS3: 7.2
fstec
3 месяца назад

Уязвимость функции formSetWanDiag() микропрограммного обеспечения маршрутизаторов Tenda G300-F, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 57%
0.00338
Низкий

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-78