CVE-2026-24101: Command Injection
An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18multi. When the condition is met, s11 will be passed into subB0488, concatenated into doSystemCmd. The value of s11 is not validated, potentially leading to a command injection vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24101?
CVE-2026-24101 is classified as a high-severity vulnerability due to its potential for remote command injection.
How do I fix CVE-2026-24101?
To fix CVE-2026-24101, update the Tenda AC15V1.0 firmware to a version that addresses this vulnerability.
What products are affected by CVE-2026-24101?
CVE-2026-24101 affects the Tenda AC15V1.0 with firmware version 15.03.05.18_multi.
What is the impact of CVE-2026-24101?
The impact of CVE-2026-24101 is that it allows attackers to execute arbitrary commands on the affected device.
Is CVE-2026-24101 exploitable remotely?
Yes, CVE-2026-24101 can be exploited remotely if the vulnerable service is accessible over the network.