CVE-2024-2854

MEDIUM

Tenda AC18 15.03.05.05 - OS Command Injection via usbName Parameter in formSetSambaConf

Title source: llm
STIX 2.1

Description

A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetSambaConf of the file /goform/setsambacfg. The manipulation of the argument usbName leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257778 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.257778
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.257778

Scores

CVSS v3 6.3
EPSS 0.0153
EPSS Percentile 81.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-78
Status published
Products (1)
tenda/ac18_firmware 15.03.05.05
Published Mar 24, 2024
Tracked Since Feb 18, 2026