0.932
EPSS

CVE-2020-10987

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: 10 | VMScore: 1000 | EPSS: 0.93271 | KEV: Exploitation Reported
Published: 13/07/2020 Updated: 14/03/2025

Vulnerability Summary

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote malicious users to execute arbitrary system commands via the deviceName POST parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tenda ac15 firmware 15.03.05.19

Github Repositories

Vulnerability Research with Binary Ninja Using Binary Ninja to find vulnerabilities in the Tenda AC15 router YouTube Video youtube/SY9bcvvlSxg Tools: Binary Ninja 40 (Free, Personal, or Commercial) binaryninja/ Using EMUX to emulate the Tenda AC15 and exploit the vulnerability: emuxexploitlabnet/ githubcom/therealsaumil/emux/ a