LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-14558: Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-14558 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Tenda AC7, AC9, and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows…

CVE-2018-14558 is a command injection vulnerability in Tenda AC7, AC9, and AC10 routers. The flaw lets an attacker send a crafted request that causes the device to run operating-system commands, which can give them control over the router and the network behind it. For IT and security teams this matters because these consumer and small-office routers often sit at the edge of a network with little monitoring; successful abuse can lead to traffic interception, lateral movement, or persistent access until the device is remediated.

Public detail is limited to the CISA description and the CWE-78 classification. Confirm exact firmware versions, attack prerequisites, and fixed releases against the vendor advisory before acting.

How it works

The weakness is CWE-78: OS command injection. On the affected Tenda models the “formsetUsbUnload” function passes untrusted input into a dosystemCmd call. An attacker who can reach the router’s web management interface crafts a goform/setUsbUnload request that injects shell metacharacters or additional commands. Because the input is not properly sanitized, the router executes those commands with the privileges of the underlying process. No further exploit mechanics are provided in the public record; treat any proof-of-concept claims as unverified until you validate them against the vendor advisory and your own lab testing.

Am I affected? How to find it in your systems

These devices are typically deployed as home, small-office, or branch-office wireless routers. Inventory steps:

If you cannot determine the firmware level, assume the device is vulnerable until proven otherwise.

How to remediate

Patch first. Apply the updates supplied by Tenda exactly as described in the vendor advisory and in the CISA required action (“Apply updates per vendor instructions”). After upgrading:

Document the change and re-scan the device to confirm the vulnerable endpoint no longer accepts the injection pattern.

If you can't patch immediately

Until a vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited router vulnerabilities can be used as an entry point for broader network compromise and data theft, even when ransomware use has not been documented for this specific CVE. If you suspect the device was reachable by untrusted parties while unpatched, treat connected systems as potentially exposed: rotate credentials that traversed the router, inspect outbound traffic history, and review endpoint and server logs for follow-on activity. You can also run a free exposure scan of your email addresses against known breach data sets to see whether any credentials associated with your domain have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTenda · AC7, AC9, and AC10 Routers
WeaknessCWE-78
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities