Back

CVE-2018-14558

CRITICAL CISA KEV

An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input.

Published: Oct 30, 2018 Modified: Jun 17, 2026
CWE-78 CWE-78

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (3)

Vendor Product Version
tenda ac7_firmware *
tenda ac9_firmware *
tenda ac10_firmware *

GitHub Security Advisory GHSA-jh5j-w2c9-jcff

An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 8.67%

Top 5% most likely to be exploited

Threat Score 71.8 / 100

CISA Known Exploited

Date Added: 2021-11-03
Due Date: 2022-05-03
Required Action:

Apply updates per vendor instructions.

Data Sources

NVD CISA KEV EPSS GitHub