CVE-2020-10987
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
- Affected products
- Tenda Ac15 Ac1900
- Tenda ac15 Firmware
- = 15.03.05.19
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 79.8% (100th percentile)
- Weakness
- CWE-78
- NVD status
- Analyzed
- Published
- 2020-07-13
CVE-2020-10987 at NVD
1 known exploit for CVE-2020-10987
Proof-of-concept code and exploit modules indexed by Sploitus