CVE-2020-10987
Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
Record summary
CVE-2020-10987 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template. CISA lists CVE-2020-10987 in KEV.
Description
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Nov 6, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AC1900 Router AC15 ModelBrowse Tenda / AC1900 Router AC15 Model | CISA | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubJaden-Bowers/Tenda-Router-VR-and-ExploitRepository PoCby Jaden-BowersStars: 0Writeup1 file
Analysis
Technical assessment
A detailed technical write-up describing how to emulate Tenda AC15 firmware with QEMU, set up networking, and manually exploit CVE-2020-10987 via a crafted curl command. It includes source code for helper components (cfm_stub, hooks.so) and a boot script, but the primary artifact is the explanatory document.
Backdoor review
No backdoor observed in reviewed code
The supplied evidence is a single README.md file that documents a legitimate proof-of-concept for CVE-2020-10987. It describes emulating Tenda AC15 firmware with QEMU, creating helper programs (cfm_stub, hooks.so) to support the emulation, and exploiting the command injection vulnerability. No concealed executable behavior, credential theft, persistence, or unrelated payloads are present. The artifact is purely documentation and does not contain any backdoor or deceptive payload.
Classification basis and observed behavior
Classification basis
The artifact is a README.md file that provides a step-by-step technical analysis, reverse engineering notes, and emulation setup instructions. It includes a curl command to manually trigger the vulnerability, but the primary content is explanatory and does not constitute a standalone, automated exploit or scanner script. The file is classified as a writeup.
README.md:1-2README.md:440-468Requirements
- Requires a valid admin session cookie (user=admin; password=md5('admin')) to pass authentication checks.
README.md:448 - Requires specific HTTP headers (Host, Origin, Referer, X-Requested-With) to pass same-origin/AJAX checks.
README.md:441-448
Observed behavior
- The write-up describes sending a POST request to /goform/setUsbUnload with a malicious deviceName parameter that is passed to doSystemCmd, resulting in arbitrary command execution.
README.md:44-52README.md:450-451 - The provided curl command injects 'touch /tmp/Hello_World' to create a file on the emulated router's filesystem as proof of command execution.
README.md:450-451README.md:460-462
Behaviors behind the backdoor verdict
Observables
- Vulnerability Exploitation
- Payload withheldThe PoC demonstrates exploiting the documented vulnerability to execute arbitrary commands on the emulated router.
README.md:44-52README.md:440-452 - Emulation Setup
- Payload withheldThe documentation provides full source code and compilation instructions for helper programs needed to emulate the firmware, which is standard for rehosting embedded firmware.
README.md:84-122README.md:138-181
What the analysis did not establish
- Evidence consists of a single README.md file; no other source files from the repository were provided.
- The analysis is based solely on the supplied text; the described code was not executed or verified.
- The artifact references external repositories and toolchains that are not included in the evidence.
- Only the README.md file was reviewed; the repository may contain other files not included in this evidence packet.
- Binary files, if any exist in the repository, were not analyzed per the evidence envelope's binary policy.
This review is limited to the supplied PoC code and context. It does not assert that the code works or is safe to execute.
Nuclei templates
1ProjectDiscoveryCRITICALTenda AC15 AC1900 version 15.03.05.19 - Command InjectionCVSS 9.8
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
Impact
Unauthenticated attackers can execute arbitrary SQL commands to access or modify database contents, potentially compromising the entire Tenda router and network configuration.
Remediation
Upgrade to a patched firmware version or replace the affected device.
Source: ProjectDiscovery