nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-5767 CVE-2018-5767
CRITICAL
Tenda AC15 Router - Remote Code Execution
Record summary
CVE-2018-5767 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 2 repository PoCs.
Description
An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.
Description source: CVE List
Exploitation context
Proofs of concept
3Catalogued exploits
ExploitDBTenda AC15 Router - Remote Code ExecutionExploitDB exploitby Tim CarringtonNot analyzed1 file
Repository PoCs
GitHubdb44k/CVE-2018-5767-AC9Repository PoCby db44kStars: 0Not analyzed3 files
GitHubScorpion-Security-Labs/CVE-2018-5767-AC9Repository PoCby Scorpion-Security-LabsStars: 0Not analyzed3 files
References
344253exploit
https://www.exploit-db.com/exploits/44253 fidusinfosec.com
https://www.fidusinfosec.com/remote-code-execution-cve-2018-5767