CVE-2020-10989: XSS
Published Jul 13, 2020
·Updated
An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute malicious payloads via the WifiName POST parameter.
Affected Software
2 affected components
Tenda ac15 firmware=15.03.05.19
Tenda Ac15
Event History
Jul 13, 2020
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-10989.
2
What is the affected software version?
The affected software version is Tenda AC15 AC1900 version 15.03.05.19.
3
What is the severity level of CVE-2020-10989?
The severity level of CVE-2020-10989 is medium with a CVSS score of 6.1.
4
How can remote attackers exploit CVE-2020-10989?
Remote attackers can exploit CVE-2020-10989 by executing malicious payloads via the WifiName POST parameter in the /goform/WifiBasicSet endpoint.
5
Are there any references related to this vulnerability?
Yes, you can find more information about CVE-2020-10989 at the following references: [link1](https://blog.securityevaluators.com/tenda-ac1900-vulnerabilities-discovered-and-exploited-e8e26aa0bc68) and [link2](https://www.ise.io/research/)