Skip to content
COOEY

EXPOSURES › CVE-2020-10987

CVE-2020-10987

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-10987 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Tenda AC1900 routers allow remote attackers to execute system commands via an unpatched vulnerability in the deviceName POST parameter.

Tenda AC1900 routers contain an unpatched remote code execution vulnerability that allows attackers to execute arbitrary system commands via the deviceName POST parameter. This failure is critical for DIB organizations because it enables full device compromise, which can lead to lateral movement, data exfiltration, and ransomware deployment. Organizations must ensure all network hardware is patched and monitored for known unpatched vulnerabilities.

Shame score — The vulnerability is unpatched and actively exploited in the wild, allowing remote attackers to execute arbitrary code on the device.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Tenda's vulnerability allowed remote code execution, a critical flaw with severe security implications, though the provided source is purely factual without commentary on Tenda's response or handling.
cooey ↗ severe-fallout -0.60
Factual reporting of a critical vulnerability; no commentary on vendor response provided in the source.
"Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.