CVE-2018-16334: Command Injection
Published Sep 2, 2018
·Updated
An issue was discovered on Tenda AC9 V15.03.05.19(6318)CN and AC10 V15.03.06.23CN devices. The mac parameter in a POST request is used directly in a doSystemCmd call, causing OS command injection.
Affected Software
4 affected components
Tendacn Ac10 Firmware<=15.03.06.23
Tendacn Ac10
Tendacn Ac9 Firmware=15.03.05.19
Tendacn Ac9
Event History
Sep 2, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-16334.
2
What devices are affected by this vulnerability?
Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices are affected by this vulnerability.
3
What is the severity of CVE-2018-16334?
The severity of CVE-2018-16334 is critical with a CVSS score of 8.8.
4
How does the vulnerability occur?
The vulnerability occurs due to the direct use of the mac parameter in a POST request in a doSystemCmd call, causing OS command injection.
5
Is there a fix available for this vulnerability?
At the moment, there is no information available regarding a fix for this vulnerability. It is recommended to follow the vendor's security advisory for updates.