CVE-2018-16334: Tendacn AC10 Firmware

High severity, CVSS 8.8. EPSS: 3.6% chance of exploitation in the next 30 days.

An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST request is used directly in a doSystemCmd call, causing OS command injection.

Affected products

  • Tendacn AC10 Firmware: up to and including 15.03.06.23
  • Tendacn AC9 Firmware: version 15.03.05.19 only

Published 2018-09-02. Last modified 2026-06-17.