Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Tenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which processes requests to the /goform/SetIPTVCfg web interface. When handling the list and vlanId parameters, the sub_ADBC0 helper function concatenates these user-supplied values into nvram set system commands using doSystemCmd, without validating or sanitizing special characters (e.g., ;, ", #). An unauthenticated or authenticated attacker can exploit this by submitting a crafted POST request, leading to arbitrary system command execution on the affected device.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Tenda AC6 安全漏洞
Vulnerability Description
Tenda AC6是中国腾达(Tenda)公司的一款无线路由器。 Tenda AC6 15.03.05.19版本存在安全漏洞,该漏洞源于formSetIptv函数在处理list和vlanId参数时未验证或清理特殊字符,可能导致执行任意系统命令。
CVSS Information
N/A
Vulnerability Type
N/A