CVE-2020-24987: Tendacn AC18 Firmware

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to incorrect authentication handling of vulnerable logincheck() function in /usr/lib/lua/ngx_authserver/ngx_wdas.lua file if the administrator UI Interface is set to "radius".

Affected products

  • Tendacn AC18 Firmware: up to and including v15.03.05.05_en; up to and including v15.03.05.19\(6318\)_cn

Published 2020-09-04. Last modified 2026-06-17.