CVE-2020-10987: Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 79.8% chance of exploitation in the next 30 days.

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

Affected products

  • Tenda AC15 Firmware: version 15.03.05.19 only

Published 2020-07-13. Last modified 2026-06-17.