ZeroHour

CVE-2024-10697

PoC large

Remote Command Injection in Tenda AC6 Router Web Interface

CVSS 4.0
5.3 medium
EPSS
26%p98
Published
()
Modified
AI analysis

CVE-2024-10697 is a command injection flaw in the formWriteFacMac handler of the Tenda AC6 router's web API at the /goform/WriteFacMac endpoint, where the 'mac' argument is not properly sanitized before being passed to a system command. A remote attacker who can reach the management interface (the CVSS 4.0 vector rates privileges required as low) can submit a crafted 'mac' value to inject and execute arbitrary operating-system commands on the device. Successful exploitation yields command execution on the router, potentially allowing control of the device, manipulation of traffic, or pivoting to connected clients. The flaw was documented in Tenda AC6 firmware version 15.03.05.19, so owners of this router running that firmware are affected. A public proof-of-concept exploit has been disclosed, and the high EPSS score of 26.2% (98th percentile) suggests a strong likelihood of exploitation attempts within 30 days, though the flaw is not yet in CISA KEV.

What to do: Check your AC6 firmware version and upgrade to the newest Tenda firmware release once available, since 15.03.05.19 is confirmed affected and no fixed version is stated in the advisory. Until patched, disable WAN-side/remote administration, restrict access to the management interface with firewall rules, and consider filtering or monitoring requests to /goform/WriteFacMac. Watch for exploitation attempts that pass unusual or overly long values in the 'mac' parameter.

Affected
Tenda AC6 firmware15.03.05.19 (version cited in the advisory; no patched version provided)
Estimated exposure
largeon the order of hundreds of thousands of deployed units, with tens of thousands plausibly internet-exposed — The Tenda AC6 is a long-selling budget consumer Wi-Fi router with a large global install base, and Tenda home-router web interfaces are frequently found exposed in public internet scans, though no official install or exposed-device count…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac of the component API Endpoint. The manipulation of the argument mac leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Vendors
tenda
Products
ac6 firmware
Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.