CVE-2017-16923 describes a critical command injection vulnerability in the app_data_center component of several Tenda AC series routers, including AC9, AC15, and AC18 models. This flaw allows remote, unauthenticated attackers on the local area network (LAN) to execute arbitrary operating system commands by sending a specially crafted GET request to the cgi-bin/luci/usbeject endpoint. The vulnerability stems from the "usbeject_process_entry" function executing a system command with unvalidated user input. With a CVSS v3.0 score of 8.8 (HIGH), this vulnerability poses a significant risk due to its low attack complexity (AC:L) and lack of required privileges (PR:N) or user interaction (UI:N). A successful exploit could lead to complete compromise of the affected device, resulting in high confidentiality, integrity, and availability impacts (C:H/I:H/A:H). While the vulnerability is severe, there is currently no evidence of active exploitation in the wild, and no public exploit code or Metasploit modules are available. Community discussion and media coverage for this CVE are also minimal, suggesting it has not garnered widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
us_ac9v1.0br_v15.03.05.14_multi_td01CPE matchmatch criteria | cpe:2.3:o:tenda:ac9_firmware:us_ac9v1.0br_v15.03.05.14_multi_td01:*:*:*:*:*:*:* | ||
ac9_kf_v15.03.05.19\(6318_\)_cnCPE matchmatch criteria | cpe:2.3:o:tenda:ac9_firmware:ac9_kf_v15.03.05.19\(6318_\)_cn:*:*:*:*:*:*:* | ||
us_ac15v1.0br_v15.03.05.18_multi_td01CPE matchmatch criteria | cpe:2.3:o:tenda:ac15_firmware:us_ac15v1.0br_v15.03.05.18_multi_td01:*:*:*:*:*:*:* | ||
us_ac15v1.0br_v15.03.05.19_multi_td01CPE matchmatch criteria | cpe:2.3:o:tenda:ac15_firmware:us_ac15v1.0br_v15.03.05.19_multi_td01:*:*:*:*:*:*:* | ||
us_ac18v1.0br_v15.03.05.05_multi_td01CPE matchmatch criteria | cpe:2.3:o:tenda:ac18_firmware:us_ac18v1.0br_v15.03.05.05_multi_td01:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.