Learn about CVE-2020-24987, a vulnerability in Tenda AC18 Routers allowing remote code execution. Find out how to mitigate the risk and secure your network.
Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to incorrect authentication handling of vulnerable logincheck() function in /usr/lib/lua/ngx_authserver/ngx_wdas.lua file if the administrator UI Interface is set to "radius".
Understanding CVE-2020-24987
This CVE involves a vulnerability in Tenda AC18 Routers that could lead to remote code execution.
What is CVE-2020-24987?
CVE-2020-24987 is a security vulnerability in Tenda AC18 Routers that allows remote attackers to execute arbitrary code due to improper authentication handling.
The Impact of CVE-2020-24987
The vulnerability could result in unauthorized remote code execution on affected Tenda AC18 Routers, potentially leading to a compromise of the device and the network it is connected to.
Technical Details of CVE-2020-24987
This section provides more in-depth technical information about the CVE.
Vulnerability Description
The vulnerability arises from incorrect authentication handling in the logincheck() function of the /usr/lib/lua/ngx_authserver/ngx_wdas.lua file when the administrator UI Interface is set to "radius" on Tenda AC18 Routers.
Affected Systems and Versions
Exploitation Mechanism
Attackers can exploit this vulnerability remotely by manipulating the authentication process through the vulnerable logincheck() function.
Mitigation and Prevention
Protecting systems from CVE-2020-24987 requires immediate actions and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates