hackmd.io
https://hackmd.io/%40aZYpdinUS2SD-yhAeHwOkw/ry-t4QfMu CVE-2021-27692
CRITICAL
Tenda g1_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2021-27692 has a selected CVSS score of 9.8 (critical).
Description
Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted "action/umountUSBPartition" request. This occurs because the "formSetUSBPartitionUmount" function executes the "doSystemCmd" function with untrusted input.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 8, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
g1_firmwareBrowse Tenda / g1_firmware | VulnCheck | Version data not supplied | |
References
3hackmd.io
https://hackmd.io/@aZYpdinUS2SD-yhAeHwOkw/ry-t4QfMu nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-27692