Critical severity9.8CISA KEVNVD Advisory· Published Jul 13, 2020· Updated Jun 17, 2026
CVE-2020-10987
CVE-2020-10987
Description
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:tenda:ac15_firmware:15.03.05.19:*:*:*:*:*:*:*
- Tenda/AC15 AC1900description
- Range: 15.03.05.19
Patches
Vulnerability mechanics
References
3- blog.securityevaluators.com/tenda-ac1900-vulnerabilities-discovered-and-exploited-e8e26aa0bc68nvdExploitThird Party Advisory
- www.ise.io/research/nvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
2- New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into ProxiesInfosecurity Magazine · Aug 14, 2026
- RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning ExploitsTrend Micro Research · Oct 9, 2025