EXPOSURES › CVE-2018-14558
CVE-2018-14558
HIGH ⌖ ON CISA KEV · EXPLOITEDTenda AC7, AC9, and AC10 routers allow remote command execution via a command injection flaw in the formsetUsbUnload function.
An attacker can execute arbitrary OS commands on these routers by sending a crafted request to the formsetUsbUnload endpoint. This is a critical failure for DIB organizations because it enables remote code execution, potentially leading to network compromise, data exfiltration, or lateral movement. Organizations must ensure these devices are patched or replaced immediately, as the vulnerability is actively exploited in the wild.
Shame score — A command injection vulnerability in consumer-grade IoT hardware that is actively exploited in the wild represents a severe, avoidable failure in secure design and patching.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.
"Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the 'formsetUsbUnload' function executes a dosystemCmd function with untrusted input."