Tenda AC1206
cpe:2.3:h:tenda:ac1206:*:*:*:*:*:*:*, +1 more
- AC1206V1.0RTL_V15.03.06.23
A command injection vulnerability exists in the Tenda AC1206 router running firmware version 15.03.06.23. The issue arises in the HTTP component, specifically within the 'formBehaviorManager' function of the '/goform/BehaviorManager' file. The vulnerability allows remote attackers to inject commands by manipulating the 'modulename', 'option', 'data', and 'switch' parameters. The 'data' parameter is particularly vulnerable, as it is executed without proper sanitization, leading to unauthorized command execution on the device.
Exploitation of this vulnerability allows for arbitrary command execution on the affected device.
The vulnerability can be reproduced by sending a POST request to the '/goform/BehaviorManager' endpoint with the 'modulename', 'option', 'switch', and 'data' parameters. The 'data' parameter can be crafted to include malicious commands, such as a command to create a file on the device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.