First published: Mon Jul 13 2020(Updated: )
An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute malicious payloads via the WifiName POST parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda ac15 firmware | =15.03.05.19 | |
Tenda AC15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-10989.
The affected software version is Tenda AC15 AC1900 version 15.03.05.19.
The severity level of CVE-2020-10989 is medium with a CVSS score of 6.1.
Remote attackers can exploit CVE-2020-10989 by executing malicious payloads via the WifiName POST parameter in the /goform/WifiBasicSet endpoint.
Yes, you can find more information about CVE-2020-10989 at the following references: [link1](https://blog.securityevaluators.com/tenda-ac1900-vulnerabilities-discovered-and-exploited-e8e26aa0bc68) and [link2](https://www.ise.io/research/)