peter bassill · operator
$ cve CVE-2018-14558 JSON

CVE-2018-14558 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 8.7% (pctl 95)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS8.74% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2022-05-03
Public exploitnone known
Published2018-10-30
Last modified2026-06-17

CISA KEV

NameTenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productTenda / AC7, AC9, and AC10 Routers
Ransomware usenone reported

Affected (6)

VendorProduct
tendaac10
tendaac10 firmware
tendaac7
tendaac7 firmware
tendaac9
tendaac9 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD