Critical severity9.8NVD Advisory· Published Jul 23, 2020· Updated Jun 17, 2026
CVE-2020-15916
CVE-2020-15916
Description
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.
Affected products
4- cpe:2.3:o:tenda:ac15_firmware:15.03.05.19:*:*:*:*:*:*:*
- Tenda/AC15description
- Range: 15.03.05.19
Patches
Vulnerability mechanics
References
1- blog.securityevaluators.com/tenda-ac1900-vulnerabilities-discovered-and-exploited-e8e26aa0bc68nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.