Back to CVE Lookup
CVE-2020-10987
CRITICAL - CVSS 9.8CWE-78
Published: 7/13/2020
Modified: 11/7/2025
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
Vulnerability Summary
CVSS v3 Score
9.8CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2 Score
10
AV:N/AC:L/Au:N/C:C/I:C/A:C