CVE-2018-18728: OS Command Injection
An issue was discovered on Tenda AC9 V15.03.05.19(6318)CN, AC15 V15.03.05.19CN, and AC18 V15.03.05.19(6318)CN devices. They allow remote code execution via shell metacharacters in the usbName field to the fastcall function with a POST request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-18728?
CVE-2018-18728 is a vulnerability found on Tenda AC9, AC15, and AC18 devices that allows remote code execution via shell metacharacters.
Which Tenda devices are affected by CVE-2018-18728?
Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices are affected.
How can an attacker exploit CVE-2018-18728?
An attacker can exploit CVE-2018-18728 by using shell metacharacters in the usbName field to the __fastcall function with a POST request.
What is the severity of CVE-2018-18728?
CVE-2018-18728 has a severity rating of 9.8 (Critical).
Is there a fix for CVE-2018-18728?
Yes, it is recommended to update the firmware of the affected Tenda devices to the latest version to mitigate this vulnerability.