CVE-2026-24107: Command Injection
Published Mar 2, 2026
·Updated
An issue was discovered in Tenda W20E V4.0brV15.11.0.6. Failure to validate the value of usbPartitionName, which is directly used in doSystemCmd, may lead to critical command injection vulnerabilities.
Affected Software
3 affected components
Tenda W20E=V4.0br_V15.11.0.6
All of the following
Tenda W20e Firmware=15.11.0.6
Tenda W20E=4.0
Event History
Mar 2, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-24107?
CVE-2026-24107 is considered a critical vulnerability due to its potential for remote command injection.
2
How do I fix CVE-2026-24107?
To mitigate CVE-2026-24107, update the Tenda W20E device firmware to a version that addresses this vulnerability.
3
What systems are affected by CVE-2026-24107?
CVE-2026-24107 specifically affects Tenda W20E with firmware version V4.0br_V15.11.0.6.
4
What is the nature of the vulnerability described in CVE-2026-24107?
CVE-2026-24107 involves improper validation of the 'usbPartitionName' variable, allowing command injection.
5
Is CVE-2026-24107 a known exploit?
Yes, there are reports indicating that CVE-2026-24107 has been successfully exploited in the wild.