Tenda AC9 Command Injection Vulnerability in the formSetSambaConf Function

Vulnerability

A command injection vulnerability has been identified in the Tenda AC9 router, specifically in the V15.03.06.42_multi firmware. The issue arises in the formSetSambaConf function, where the usbname parameter can be manipulated to execute arbitrary commands. This vulnerability can be exploited by sending a crafted request that includes the malicious command payload.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device.

Reproduction

To reproduce this vulnerability, send a request to the '/goform/SetSambaCfg' endpoint with the 'action' parameter set to 'del' and the 'usbName' parameter containing the injected command, such as a command to create a file in the '/tmp' directory.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
6.2
remediation
0.0
relevance
0.0
threat
6.7
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.