Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/t0hka1/Tenda-AC15-Exp/blob/master/Tenda%20AC15%20V15.03.05.20%20Exp.md | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    24 Sep 2024, 18:10
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/t0hka1/Tenda-AC15-Exp/blob/master/Tenda%20AC15%20V15.03.05.20%20Exp.md - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:o:tenda:ac15_firmware:15.03.05.20:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac15:-:*:*:*:*:*:*:* | |
| Summary | 
 | |
| First Time | Tenda ac15 Firmware Tenda Tenda ac15 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 9.8 | 
10 Sep 2024, 20:35
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 8.0 | 
| CWE | CWE-77 | 
10 Sep 2024, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-09-10 16:15
Updated : 2024-09-24 18:10
NVD link : CVE-2023-36103
Mitre link : CVE-2023-36103
CVE.ORG link : CVE-2023-36103
JSON object : View
Products Affected
                tenda
- ac15
- ac15_firmware
CWE
                
                    
                        
                        CWE-77
                        
            Improper Neutralization of Special Elements used in a Command ('Command Injection')
