Command Injection Vulnerability in Tenda G1 and G3 Routers
CVE-2021-45990
9.8CRITICAL
What is CVE-2021-45990?
Tenda routers G1 and G3 are vulnerable to a command injection attack through the 'uploadPicture' function. By manipulating the 'pic_name' parameter, attackers can execute arbitrary commands on the affected devices, potentially compromising network integrity and exposing them to further attacks.