Command Injection Vulnerability in Tenda G1 and G3 Routers
CVE-2021-27692
9.8CRITICAL
What is CVE-2021-27692?
A command injection vulnerability exists in Tenda G1 and G3 routers, where attackers can execute arbitrary OS commands remotely. This security flaw arises from the improper handling of user inputs in the 'formSetUSBPartitionUmount' function, which directly invokes the 'doSystemCmd' function without adequate input validation. By sending crafted requests to the 'action/umountUSBPartition' endpoint, an attacker can manipulate the system and gain unauthorized access, potentially compromising the integrity of the device and its network environment.