Tenda AC15
cpe:2.3:h:tenda:ac15:*:*:*:*:*:*:*, +3 more
- V15.03.05.18_multi
A command injection vulnerability has been identified in the Tenda AC15 router, specifically in the firmware version V15.03.05.18_multi. The issue arises within the goform/formSetIptv endpoint, where the parameter s1_1 is passed to a function without proper validation. This lack of input sanitization could allow an attacker to inject and execute arbitrary commands on the device.
Exploitation of this vulnerability could lead to unauthorized command execution on the affected router.
To reproduce this vulnerability, send a POST request to the /goform/formSetIptv endpoint. Include the s1_1 parameter with a value that contains the desired command payload. The injected command will be executed on the router's system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.