CVE-2020-10986: CSRF
Published Jul 13, 2020
·Updated
A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause denial of service via a payload hosted by an attacker-controlled web page.
Affected Software
2 affected components
Tenda ac15 firmware=15.03.05.19
Tenda Ac15
Event History
Jul 13, 2020
CVE Published
via MITRE·05:59 PM
Data Sourced
via MITRE·05:59 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of Tenda AC15 AC1900?
The vulnerability ID of Tenda AC15 AC1900 is CVE-2020-10986.
2
What is the severity level of CVE-2020-10986?
The severity level of CVE-2020-10986 is high (6.5).
3
How does CVE-2020-10986 affect Tenda AC15 AC1900 version 15.03.05.19?
CVE-2020-10986 allows remote attackers to reboot the device and cause denial of service via a payload hosted by an attacker-controlled web page.
4
Is Tenda AC15 AC1900 version 15.03.05.19 vulnerable to CVE-2020-10986?
Yes, Tenda AC15 AC1900 version 15.03.05.19 is vulnerable to CVE-2020-10986.
5
How can I mitigate the CSRF issue in Tenda AC15 AC1900 version 15.03.05.19?
To mitigate the CSRF issue, update the firmware of Tenda AC15 AC1900 to a version that addresses the vulnerability.