CVE-2020-26728: Critical severity tenda ac9 vulnerability
A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42multi and Tenda AC9 V1.0 V15.03.05.19(6318)CN which allows for remote code execution via shell metacharacters in the guestuser field to the fastcall function with a POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26728?
The severity of CVE-2020-26728 is critical with a CVSS score of 9.8.
What is the vulnerability description of CVE-2020-26728?
CVE-2020-26728 is a vulnerability in Tenda AC9 routers that allows for remote code execution via shell metacharacters in the guestuser field.
Which versions of Tenda AC9 firmware are affected by CVE-2020-26728?
Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN are affected by CVE-2020-26728.
How can remote code execution be achieved in CVE-2020-26728?
Remote code execution can be achieved in CVE-2020-26728 by exploiting shell metacharacters in the guestuser field through a POST request.
Are the Tenda AC9 versions 3.0 and 1.0 vulnerable to CVE-2020-26728?
No, Tenda AC9 versions 3.0 and 1.0 are not vulnerable to CVE-2020-26728.