Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 16 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection in Tenda AC15 Router FormSetIptv |
Tue, 03 Mar 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda ac15 Tenda ac15 Firmware |
|
| CPEs | cpe:2.3:h:tenda:ac15:1.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac15_firmware:15.03.05.18_multi:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda
Tenda ac15 Tenda ac15 Firmware |
Mon, 02 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-78 | |
| Metrics |
cvssV3_1
|
Mon, 02 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1 is not validated, potentially leading to a command injection vulnerability. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-02T16:02:26.391Z
Reserved: 2026-01-21T00:00:00.000Z
Link: CVE-2026-24101
Updated: 2026-03-02T16:02:18.708Z
Status : Analyzed
Published: 2026-03-02T16:16:24.407
Modified: 2026-03-03T19:44:19.120
Link: CVE-2026-24101
No data.
OpenCVE Enrichment
Updated: 2026-04-16T14:45:25Z