CVE-2018-16334
02.09.2018, 03:29
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST request is used directly in a doSystemCmd call, causing OS command injection.
Vendor | Product | Version |
---|---|---|
tendacn | ac10_firmware | 𝑥 ≤ 15.03.06.23 |
tendacn | ac9_firmware | 15.03.05.19 |
𝑥
= Vulnerable software versions