CVE-2020-10987

CRITICAL KEV NUCLEI

Tenda AC15 AC1900 <15.03.05.19 - RCE

Title source: llm

Description

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

Exploits (1)

nomisec WRITEUP
by Jaden-Bowers · poc
https://github.com/Jaden-Bowers/Tenda-Router-VR-and-Exploit

Nuclei Templates (1)

Tenda AC15 AC1900 version 15.03.05.19 - Command Injection
CRITICALby pussycat0x
Shodan: http.title:"tenda wifi"

Scores

CVSS v3 9.8
EPSS 0.9389
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2020-11-06
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2020-3386
CWE
CWE-78
Status published
Products (1)
tenda/ac15_firmware 15.03.05.19
Published Jul 13, 2020
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026