CVE-2020-15916
CRITICAL EXPLOITEDTenda Ac15 Firmware - OS Command Injection
Title source: ruleDescription
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.
Exploits (2)
Scores
CVSS v3
9.8
EPSS
0.0363
EPSS Percentile
87.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2024-02-22
CWE
CWE-78
Status
published
Products (1)
tenda/ac15_firmware
15.03.05.19
Published
Jul 23, 2020
Tracked Since
Feb 18, 2026