Vulnerability record · CVE-2018-5767 · published 15 February 2018
CVE-2018-5767: Tenda AC15 router remote code execution via COOKIE header password parameter
Tendacn · Ac15 Firmware
Tenda AC15 firmware V15.03.1.16_multi fails to properly validate the password parameter in the COOKIE header, allowing command injection. A remote, unauthenticated attacker can exploit this to execute arbitrary code on the device. The flaw is critical because it requires no credentials or user interaction and gives full control of the router.
Description
An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit code available, and very high EPSS probability make this an urgent risk for exposed Tenda AC15 devices.
What it is
Tenda AC15 firmware V15.03.1.16_multi fails to properly validate the password parameter in the COOKIE header, allowing command injection. A remote, unauthenticated attacker can exploit this to execute arbitrary code on the device. The flaw is critical because it requires no credentials or user interaction and gives full control of the router.
Impact
An attacker gains remote code execution with the privileges of the affected service, allowing full compromise of the device. This can lead to persistent access, traffic interception, or use of the router as a pivot into the internal network.
Attack surface
The vulnerability is reachable over the network via HTTP requests to the router's web interface, specifically by crafting the password parameter in the COOKIE header. No authentication or user interaction is required, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Public exploit code exists (Exploit-DB 44253 and a technical advisory from Fidus InfoSec), and EPSS estimates a 47.4% probability of exploitation in the next 30 days (98.8th percentile). The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is documented in this record.
What to do
- Apply the latest firmware update from Tenda for the AC15; if no patch is available, replace the device or isolate it from untrusted networks.
- Disable remote administration and restrict web interface access to trusted management networks only.
- Place the router behind a firewall that blocks inbound access to its web management port from the internet.
- Monitor vendor advisories for a fixed firmware version and upgrade as soon as it is released.
- If the device cannot be patched, consider network segmentation to limit lateral movement from a compromised router.
Detection
- Inspect HTTP request logs for COOKIE headers containing unusual characters or shell metacharacters in the password parameter.
- Monitor for outbound connections from the router to unexpected external IP addresses or command-and-control infrastructure.
- Use network intrusion detection signatures that flag known exploit patterns for CVE-2018-5767.
- Audit router configuration changes and unexpected process execution on the device if logging is available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.exploit-db.com/exploits/44253/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.fidusinfosec.com/remote-code-execution-cve-2018-5767/ | ExploitTechnical DescriptionThird Party Advisory |
| https://www.exploit-db.com/exploits/44253/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.fidusinfosec.com/remote-code-execution-cve-2018-5767/ | ExploitTechnical DescriptionThird Party Advisory |
Track CVE-2018-5767 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-5767), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.