← All CVEs

CVE-2021-27691

critical · 9.8

Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs because the "formSetDebugCfg" function executes glibc's system function with untrusted input.

9.8
CVSS
25.2%
EPSS (exploit prob.)
98th
EPSS percentile
2021-04-16
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78CWE-119

Affected products

VendorProductAffected versions
tendacng0_firmware15.11.0.5(5876)_cn
tendacng0_firmware15.11.0.6(9039)_cn
tendacng0all versions
tendacng1_firmware15.11.0.16(9024)_cn
tendacng1_firmware15.11.0.17(9502)_cn
tendacng1all versions
tendacng3_firmware15.11.0.16(9024)_cn
tendacng3_firmware15.11.0.17(9502)_cn
tendacng3all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-27691