Vulnerability Details CVE-2024-30891
A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters for arbitrary command execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.6%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2024-30891
-
-
cpe:2.3:o:tenda:ac18_firmware:15.03.05.05