Impact
This vulnerability is a CWE-77 OS command injection flaw that exists in the "/goform/fast_setting_internet_set"18 router firmware version 15.03.05.05. An attacker can supply a specially crafted payload in the "mac" parameter, causing the router to execute arbitrary operating system commands. The flaw does not require authentication and can be triggered by any host that can reach the router’s HTTP management interface.
Affected Systems
The affected device is the Tenda AC18 wireless router running firmware 15.03.05.05; no other vendors or product families are listed as impacted.
Risk and Exploitability
The CVSS score is 6.5, indicating medium severity. The EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation in the wild. The. Because the flaw is triggered via an unauthenticated HTTP request, the likely attack vector is network‑based, inferred from the lack of authentication and the exposed admin interface.
OpenCVE Enrichment