← Back to browse · API

CVE-2026-24101

Severity
CRITICAL
CVSS
9.8
EPSS
0.01671
Risk score
39.78
CISA KEV
No
PoC
No
Published
2026-03-02
Modified
2026-03-02
First seen
2026-08-06
Aliases
CNVD-2026-13536, EUVD-2026-9196, GHSA-MCV3-6WFV-RV64
Products
Tenda AC15 15.03.05.18_multi, n/a:n/a n/a
Sources
cnvd CNVD-2026-13536
euvd EUVD-2026-9196

Description

An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1 is not validated, potentially leading to a command injection vulnerability.

References