ZeroHour

CVE-2020-15916

PoC
CVSS 3.1
9.8 critical
EPSS
3%p88
Published
()
Modified
Description

goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.

Vendors
tenda
Products
ac15 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.