Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs because the "formSetDebugCfg" function executes glibc's system function with untrusted input.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-14433 Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs because the "formSetDebugCfg" function executes glibc's system function with untrusted input.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T21:26:10.746Z

Reserved: 2021-02-25T00:00:00

Link: CVE-2021-27691

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-16T00:15:12.007

Modified: 2024-11-21T05:58:25.883

Link: CVE-2021-27691

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.