Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-26728

A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allows for remote code execution via shell metacharacters in the guestuser field to the __fastcall function with a POST request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.034
EPSS Ranking 87.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-26728
  • Tenda » Ac9 » Version: 1.0
    cpe:2.3:h:tenda:ac9:1.0
  • Tenda » Ac9 » Version: 3.0
    cpe:2.3:h:tenda:ac9:3.0
  • Tenda » Ac9 Firmware » Version: 15.03.05.19(6318)_cn
    cpe:2.3:o:tenda:ac9_firmware:15.03.05.19(6318)_cn
  • Tenda » Ac9 Firmware » Version: 15.03.06.42_multi
    cpe:2.3:o:tenda:ac9_firmware:15.03.06.42_multi


Contact Us

Shodan ® - All rights reserved