← Back

CVE-2021-27691

nvd nist
Published: Apr 16, 2021Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs because the "formSetDebugCfg" function executes glibc's system function with untrusted input.

Affected (6)

3 products
G0 Firmware
G1 Firmware
G3 Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Tendacn
Version 15.11.0.5(5876)_cn
Version 15.11.0.6(9039)_cn
Running on/withPlatform Versions
Tendacn
G0
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Tendacn
Version 15.11.0.16(9024)_cn
Version 15.11.0.17(9502)_cn
Running on/withPlatform Versions
Tendacn
G1
All versions
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Tendacn
Version 15.11.0.16(9024)_cn
Version 15.11.0.17(9502)_cn
Running on/withPlatform Versions
Tendacn
G3
All versions

References (2)

Timeline

No history available yet.