Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
2025-05-02T15:15:49.227
2025-05-27T14:21:40.517
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | tenda | ac9_firmware | 15.03.06.42_multi | Yes |
| Hardware | tenda | ac9 | - | No |