Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

Tenda AC15 V15.03.05.18_multi: Command Injection in USB Unload Feature

CVE-2026-24105
Summary

The Tenda AC15 router's USB unload feature is vulnerable to a security risk. If an attacker sends malicious data, they might be able to execute unauthorized commands on the router. Update the router's firmware to the latest version to protect it.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
tenda ac15_firmware 15.03.05.18 –
Original title
An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a command injection vulnerability if injected into...
Original description
An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a command injection vulnerability if injected into doSystemCmd.
nvd CVSS3.1 9.8
Vulnerability type
CWE-94 Code Injection
Published: 2 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026