A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allows for remote code execution via shell metacharacters in the guestuser field to the __fastcall function with a POST request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ac9_firmware | Tenda | 15.03.06.42_multi (including) | 15.03.06.42_multi (including) |