CVE-2026-24105: Command Injection
Published Mar 2, 2026
·Updated
An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18multi. The value of v1 was not checked, potentially leading to a command injection vulnerability if injected into doSystemCmd.
Affected Software
3 affected components
Tenda Ac15
All of the following
Tenda ac15 firmware=15.03.05.18
Tenda Ac15=1.0
Event History
Mar 2, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-24105?
CVE-2026-24105 is classified as a medium severity vulnerability due to its potential for command injection.
2
How do I fix CVE-2026-24105?
To fix CVE-2026-24105, update the Tenda AC15 firmware to the latest version where the vulnerability is patched.
3
What is the impact of CVE-2026-24105?
The impact of CVE-2026-24105 can allow an attacker to execute arbitrary commands on the affected device.
4
Which devices are affected by CVE-2026-24105?
CVE-2026-24105 affects the Tenda AC15 V1.0 device running firmware version 15.03.05.18.
5
Is CVE-2026-24105 remotely exploitable?
Yes, CVE-2026-24105 can potentially be exploited remotely if an attacker sends crafted input to the vulnerable function.