CVE-2018-14558
Description
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input.
In plain language
AI Act nowThis is a critical security hole in certain Tenda router firmware that lets an attacker take full control if they can reach the router’s web page—so yes, a typical small business should worry if your device is exposed to the network.
CVE-2018-14558 is an unauthenticated command injection in Tenda ac7 firmware, ac9 firmware, and ac10 firmware where a crafted HTTP request to the goform/setUsbUnload endpoint can inject shell commands for full remote control.
What to do now
- Check whether your Tenda AC7, AC9, or AC10 router’s current firmware version is within the affected range (AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, AC10 through V15.03.06.23_CN).
- Verify whether the router’s web interface is reachable from outside your local network (for example, via the WAN/Internet), not just from your internal computers/phones.
- If it is Internet-reachable, immediately block inbound access to the router’s web interface from the Internet using your firewall/router rules (allow only trusted internal IPs).
- Contact your vendor/support channel and request the specific fixed firmware for CVE-2018-14558 for your exact model and current firmware; install it as soon as a version is provided.
- If you cannot obtain a fixed firmware promptly, treat the device as compromised-risk: keep it isolated from the Internet and restrict all inbound management access until patched.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Ботнет Evooo1Bot превращает зараженные устройства в проксиru-ru·Хакер (xakep.ru)· Exploited Alcatel ddos-botnet
- Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoSen·Dark Reading· Exploited Alcatel ddos-botnet
- Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxiesen·The Hacker News· Exploited Alcatel OmniPCX Enterprise ddos-botnet
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-14558 and every CVE in our database. Create a free account — no credit card required.
Create Free Account