CVE-2019-5071: OS Command Injection
An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gigabit WiFi Route (AC9V1.0 Firmware V15.03.05.16multiTRU). A specially crafted HTTP POST request can cause a command injection in the DNS1 post parameters, resulting in code execution. An attacker can send HTTP POST request with command to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5071?
CVE-2019-5071 has a high severity rating due to its potential for command injection vulnerabilities.
How do I fix CVE-2019-5071?
To fix CVE-2019-5071, you should update the router firmware to the latest version provided by Tenda.
Which devices are affected by CVE-2019-5071?
CVE-2019-5071 affects Tenda AC9 Router running firmware versions 15.03.05.14_en and 15.03.05.16multiTRU.
What can an attacker achieve with CVE-2019-5071?
An attacker exploiting CVE-2019-5071 can execute arbitrary commands on the affected router, potentially compromising the device.
Is CVE-2019-5071 being actively exploited in the wild?
There is no specific indication that CVE-2019-5071 is currently being actively exploited, but it remains a significant risk if left unpatched.