CVE-2018-14558 Details
Description
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input.
A command injection vulnerability has been identified in Tenda AC7, AC9, and AC10 routers running specific firmware versions. This vulnerability allows attackers to execute arbitrary operating system commands by sending a crafted request to the 'goform/setUsbUnload' endpoint. The issue arises because the 'formsetUsbUnload' function passes untrusted input to a command execution function, creating an opportunity for exploitation.
Users are advised to update their devices to the latest firmware version. Instructions for updating can be found on the Tenda official website or through the Tenda customer support channels.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-14558 | CISA-ADP | US Government Resource |
| https://github.com/zsjevilhex/iot/blob/master/route/tenda/tenda-01/Tenda.md | CVE | Broken LinkExploitThird Party Advisory |
| https://github.com/zsjevilhex/iot/blob/master/route/tenda/tenda-01/Tenda.md | [email protected] | Broken LinkExploitThird Party Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability | Nov 3, 2021 | May 3, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| tenda ac7 firmware | <= 15.03.06.44_cn |
CPE
Remediation
| |
| tenda ac7 | All versions |
CPE
Remediation
| |
| tenda ac9 firmware | <= 15.03.05.19\(6318\)_cn |
CPE
Remediation
| |
| tenda ac9 | All versions |
CPE
Remediation
| |
| tenda ac10 firmware | <= 15.03.06.23_cn |
CPE
Remediation
| |
| tenda ac10 | All versions |
CPE
Remediation
| |
Change History
13 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 7, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 20, 2025 | Modified Analysis | [email protected] |
| Feb 4, 2025 | CVE Modified | CISA-ADP |
| Jan 27, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Jan 29, 2019 | Initial Analysis | [email protected] |