Record summary

CVE-2018-5767 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 2 repository PoCs.

Description

An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
2

Proofs of concept

3

Catalogued exploits

ExploitDBTenda AC15 Router - Remote Code ExecutionExploitDB exploitby Tim CarringtonNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubdb44k/CVE-2018-5767-AC9Repository PoCby db44kStars: 0Not analyzed3 files

6.5 KiB

GitHub

PoC details
GitHubScorpion-Security-Labs/CVE-2018-5767-AC9Repository PoCby Scorpion-Security-LabsStars: 0Not analyzed3 files

6.8 KiB

GitHub

PoC details

References

3