Home
Description
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
References
github.com/...ForIoT/tree/main/Tenda_AC/AC9_formsetUsbUnload
github.com/...ForIoT/tree/main/Tenda_AC/AC9_formsetUsbUnload