8.8
CVSSv3

CVE-2018-16334

Published: 02/09/2018 Updated: 25/10/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

An issue exists on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST request is used directly in a doSystemCmd call, causing OS command injection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tendacn ac10_firmware

tendacn ac9_firmware 15.03.05.19