CVE-2020-24987: Critical severity tenda ac18 firmware vulnerability
Tenda AC18 Router through V15.03.05.05EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to incorrect authentication handling of vulnerable logincheck() function in /usr/lib/lua/ngxauthserver/ngxwdas.lua file if the administrator UI Interface is set to "radius".
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24987?
CVE-2020-24987 refers to a vulnerability found in Tenda AC18 routers which could allow remote code execution due to incorrect authentication handling.
How severe is CVE-2020-24987?
CVE-2020-24987 has a severity rating of 9.8 (Critical).
How does CVE-2020-24987 affect Tenda AC18 routers?
CVE-2020-24987 affects Tenda AC18 routers running firmware versions up to v15.03.05.05_EN and v15.03.05.19(6318)_cn.
How can the CVE-2020-24987 vulnerability be exploited?
The CVE-2020-24987 vulnerability can be exploited by exploiting the incorrect authentication handling in the vulnerable logincheck() function.
Is there a fix available for CVE-2020-24987?
It is recommended to update the firmware of the Tenda AC18 router to the latest version provided by the vendor to fix the CVE-2020-24987 vulnerability.