Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.
2024-09-10T16:15:18.380
2024-09-24T18:10:16.207
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | tenda | ac15_firmware | 15.03.05.20 | Yes |
| Hardware | tenda | ac15 | - | No |