Tenda Vulnerability Key Information Vendor: Tenda Product: O3V2 Version: 1.0.0.12(3880) Type: Remote Command Execution Author: Jiaqi Peng Institution: pengjiaqian@iie.ac.cn Vulnerability Description Remote Command Execution The vulnerability exists in the function where the parameter is directly passed by the attacker. The initial input is extracted and causes command injection. Vulnerable Function ( ) Proof of Concept (PoC) Set as , and the router will execute it. Result A shell is obtained.