Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Tenda AC9/AC15 exeCommand formexeCommand os command injection
Vulnerability Description
A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manipulation of the argument cmdinput causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Tenda AC9和Tenda AC15 操作系统命令注入漏洞
Vulnerability Description
Tenda AC9和Tenda AC15都是中国腾达(Tenda)公司的一款无线路由器。 Tenda AC9和Tenda AC15 15.03.05.14版本存在操作系统命令注入漏洞,该漏洞源于文件/goform/exeCommand中函数formexeCommand对参数cmdinput的错误操作,可能导致os命令注入。
CVSS Information
N/A
Vulnerability Type
N/A