CVE-2020-10987
CRITICAL KEV NUCLEITenda AC15 AC1900 <15.03.05.19 - RCE
Title source: llmDescription
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
Exploits (1)
Nuclei Templates (1)
Tenda AC15 AC1900 version 15.03.05.19 - Command Injection
CRITICALby pussycat0x
Shodan:
http.title:"tenda wifi"
References (3)
Scores
CVSS v3
9.8
EPSS
0.9389
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2021-11-03
VulnCheck KEV
2020-11-06
InTheWild.io
2021-07-23
ENISA EUVD
EUVD-2020-3386
CWE
CWE-78
Status
published
Products (1)
tenda/ac15_firmware
15.03.05.19
Published
Jul 13, 2020
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026