ZeroHour

CVE-2024-9793

PoC ×2

Command Injection in Tenda AC1206 Router /goform/ate Interface

CVSS 4.0
5.3 medium
EPSS
23%p98
Published
()
Modified
AI analysis

Tenda AC1206 routers running firmware up to and including 15.03.06.23 are affected by an OS command injection flaw (CWE-77/CWE-78) in the ate_iwpriv_set and ate_ifconfig_set handlers of the /goform/ate endpoint. An attacker can trigger it remotely by submitting crafted input to this web interface, which the router passes to shell commands without adequate sanitization; the CVSS 4.0 vector (PR:L) indicates low-privilege authentication is required. Successful exploitation allows execution of arbitrary commands on the router, which can lead to full device compromise and a foothold on the local network. All Tenda AC1206 deployments on firmware up to 15.03.06.23 are affected. Public proof-of-concept exploits have been published, there is no confirmed in-the-wild exploitation yet, and the vendor was notified but did not respond, so no fixed firmware is confirmed.

What to do: Do not expose the router's web management interface (including /goform/ate) to the internet, and use strong admin credentials since the attack vector requires authentication. Because Tenda did not respond and no fixed firmware version is confirmed, monitor the vendor for an update and validate whether your deployed firmware is at or below 15.03.06.23; consider testing the published PoC conditions against your devices.

Affected
Tenda AC1206 router firmwareup to and including 15.03.06.23
Estimated exposure
unknown; plausibly on the order of 100,000s of consumer routers, but no per-model install or internet-exposure counts are published — No authoritative install-base or internet-exposed-device counts exist for this specific older Tenda retail model, so the estimate relies only on Tenda's high-volume consumer-router distribution pattern and is clearly an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconfig_set of the file /goform/ate. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vendors
tenda
Products
ac1206 firmware
Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.