Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qvqp-rwfh-7f5j

Опубликовано: 11 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2
CVSS3: 4.7

Описание

A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

EPSS

Процентиль: 90%
0.04412
Низкий

2 Low

CVSS4

4.7 Medium

CVSS3

Дефекты

CWE-77
CWE-78

Связанные уязвимости

CVSS3: 4.7
nvd
3 месяца назад

A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 7.2
fstec
3 месяца назад

Уязвимость функцию get_log_file() микропрограммного обеспечения маршрутизаторов Tenda AC6, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 90%
0.04412
Низкий

2 Low

CVSS4

4.7 Medium

CVSS3

Дефекты

CWE-77
CWE-78