Overview
Original source dataCommand Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs because the "formSetDebugCfg" function executes glibc's system function with untrusted input.
Affected products and scope
CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Technical details
CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Exploitability
CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Technical impact
CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Business impact
CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Remediation
CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
Detection
CyStack is analyzing this vulnerability. The page will update automatically when the analysis is ready.
