Skip to content
COOEY

EXPOSURES › CVE-2018-14558

CVE-2018-14558

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-14558 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Tenda AC7, AC9, and AC10 routers allow remote command execution via a command injection flaw in the formsetUsbUnload function.

An attacker can execute arbitrary OS commands on these routers by sending a crafted request to the formsetUsbUnload endpoint. This is a critical failure for DIB organizations because it enables remote code execution, potentially leading to network compromise, data exfiltration, or lateral movement. Organizations must ensure these devices are patched or replaced immediately, as the vulnerability is actively exploited in the wild.

Shame score — A command injection vulnerability in consumer-grade IoT hardware that is actively exploited in the wild represents a severe, avoidable failure in secure design and patching.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Command injection in consumer routers is a severe security failure, allowing full OS command execution, though the provided source is a neutral NVD entry without commentary on Tenda's response.
cooey ↗ severe-fallout +0.00
neutral
"Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the 'formsetUsbUnload' function executes a dosystemCmd function with untrusted input."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.