CVE-2018-14558: Tenda AC7, AC9, and AC10 Routers
EPSS8.5%No. 1314 of 1739 in KEV
CVE year2018~3 yrs before listing
Same vendor in KEV3
Same product1
| Field | Value |
|---|---|
| Vendor | Tenda |
| Product | AC7, AC9, and AC10 Routers |
| Name | Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability |
| Added to KEV | 2021-11-03 |
| US federal due date | 2022-05-03 |
| Ransomware use | Unknown |
| CWE | CWE-78 |
CISA description
Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Tenda AC7, AC9, and AC10 Routers vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03.