CVE-2020-10987
Description
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
In plain language
AI Act nowIf you run a Tenda AC15 AC1900 router on firmware 15.03.05.19, attackers can send a single network request to make the router run commands—this should be treated as an urgent, fix-now problem.
CVE-2020-10987 is an unauthenticated remote command execution in the Tenda AC15 AC1900 web endpoint /goform/setUsbUnload, triggered by a crafted POST request (deviceName parameter) that makes the device execute arbitrary system commands; the device is reachable in default configuration.
What to do now
- Check whether your Tenda AC15 AC1900 router is running firmware 15.03.05.19 and whether /goform/setUsbUnload is reachable from your network.
- Contact your router vendor/IT support for the official firmware update for Tenda AC15 AC1900 that fixes CVE-2020-10987, and plan an immediate upgrade.
- Until you patch, block access to the router’s web management endpoints from the internet (only allow management from your internal network/VPN, and deny WAN-originated requests).
- After updating, verify the router is no longer on 15.03.05.19 and review router and web-access logs for any requests to /goform/setUsbUnload.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Ботнет Evooo1Bot превращает зараженные устройства в проксиru-ru·Хакер (xakep.ru)· Exploited Alcatel ddos-botnet
- Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoSen·Dark Reading· Exploited Alcatel ddos-botnet
- Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxiesen·The Hacker News· Exploited Alcatel OmniPCX Enterprise ddos-botnet
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2020-10987 and every CVE in our database. Create a free account — no credit card required.
Create Free Account