#VU22915 OS Command Injection in AC9 Router AC1200 Smart Dual-Band Gigabit WiFi Router - CVE-2019-5072
Published: November 22, 2019
AC9 Router AC1200 Smart Dual-Band Gigabit WiFi Router
Shenzhen Tenda Technology Co.,Ltd.
Description
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the "dns2" POST parameter in the "/goform/WanParameterSetting" resource. A local user attacker can send a specially crafted HTTP POST request and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.