An issue was discovered on Tenda AC9 V15.03.05.19(6318)CN, AC15 V15.03.05.19CN, and AC18 V15.03.05.19(6318)CN devices. They allow remote code execution via shell metacharacters in the usbName field to the fastcall function with a POST request.
A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42multi and Tenda AC9 V1.0 V15.03.05.19(6318)CN which allows for remote code execution via shell metacharacters in the guestuser field to the fastcall function with a POST request.