Tenda AC9 V15.03.06.42_multi was found to contain a...
Critical severity
Unreviewed
Published
May 2, 2025
to the GitHub Advisory Database
•
Updated May 6, 2025
Description
Published by the National Vulnerability Database
May 2, 2025
Published to the GitHub Advisory Database
May 2, 2025
Last updated
May 6, 2025
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
References