CVE-2024-10697
PoC largeRemote Command Injection in Tenda AC6 Router Web Interface
CVE-2024-10697 is a command injection flaw in the formWriteFacMac handler of the Tenda AC6 router's web API at the /goform/WriteFacMac endpoint, where the 'mac' argument is not properly sanitized before being passed to a system command. A remote attacker who can reach the management interface (the CVSS 4.0 vector rates privileges required as low) can submit a crafted 'mac' value to inject and execute arbitrary operating-system commands on the device. Successful exploitation yields command execution on the router, potentially allowing control of the device, manipulation of traffic, or pivoting to connected clients. The flaw was documented in Tenda AC6 firmware version 15.03.05.19, so owners of this router running that firmware are affected. A public proof-of-concept exploit has been disclosed, and the high EPSS score of 26.2% (98th percentile) suggests a strong likelihood of exploitation attempts within 30 days, though the flaw is not yet in CISA KEV.
What to do: Check your AC6 firmware version and upgrade to the newest Tenda firmware release once available, since 15.03.05.19 is confirmed affected and no fixed version is stated in the advisory. Until patched, disable WAN-side/remote administration, restrict access to the management interface with firewall rules, and consider filtering or monitoring requests to /goform/WriteFacMac. Watch for exploitation attempts that pass unusual or overly long values in the 'mac' parameter.
| Tenda AC6 firmware | 15.03.05.19 (version cited in the advisory; no patched version provided) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac of the component API Endpoint. The manipulation of the argument mac leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
- Vendors
- tenda
- Products
- ac6 firmware
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.