CVE-2018-18728
EUVD-2018-1044429.10.2018, 12:29
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tenda | ac9_firmware | 15.03.05.19\(6318\)_cn |
| tenda | ac15_firmware | 15.03.05.19_cn:_cn |
| tenda | ac18_firmware | 15.03.05.19\(6318\)_cn |
𝑥
= Vulnerable software versions