EXPOSURES › CVE-2020-10987
CVE-2020-10987
HIGH ⌖ ON CISA KEV · EXPLOITEDTenda AC1900 routers allow remote attackers to execute system commands via an unpatched vulnerability in the deviceName POST parameter.
Tenda AC1900 routers contain an unpatched remote code execution vulnerability that allows attackers to execute arbitrary system commands via the deviceName POST parameter. This failure is critical for DIB organizations because it enables full device compromise, which can lead to lateral movement, data exfiltration, and ransomware deployment. Organizations must ensure all network hardware is patched and monitored for known unpatched vulnerabilities.
Shame score — The vulnerability is unpatched and actively exploited in the wild, allowing remote attackers to execute arbitrary code on the device.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter.
"Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter."