CVE-2018-5767

CRITICAL

Tenda AC15 <V15.03.1.16_multi - RCE

Title source: llm

Description

An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.

Exploits (3)

nomisec WORKING POC
by Scorpion-Security-Labs · poc
https://github.com/Scorpion-Security-Labs/CVE-2018-5767-AC9
nomisec WORKING POC
by db44k · poc
https://github.com/db44k/CVE-2018-5767-AC9
exploitdb WORKING POC
by Tim Carrington · pythonremotehardware
https://www.exploit-db.com/exploits/44253

Scores

CVSS v3 9.8
EPSS 0.6666
EPSS Percentile 98.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-20
Status published

Affected Products (1)

tendacn/ac15_firmware

Timeline

Published Feb 15, 2018
Tracked Since Feb 18, 2026