Exploited Vulnerabilities Daily
🌐 English

Home › Tenda

CVE-2018-14558: Tenda AC7, AC9, and AC10 Routers

EPSS8.5%No. 1314 of 1739 in KEV
CVE year2018~3 yrs before listing
Same vendor in KEV3
Same product1
FieldValue
VendorTenda
ProductAC7, AC9, and AC10 Routers
NameTenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
Added to KEV2021-11-03
US federal due date2022-05-03
Ransomware useUnknown
CWECWE-78

CISA description

Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.

NVD — CVE-2018-14558

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Tenda AC7, AC9, and AC10 Routers vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03.