SOURCE FACT
Tenda · AC7, AC9, and AC10 Routers
Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.
Required action
Apply updates per vendor instructions.
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2018-14558
View source evidence →