CVE-2026-24107 | Tenda W20E 15.11.0.6 doSystemCmd usbPartitionName command injection
A vulnerability described as critical has been identified in Tenda W20E 15.11.0.6. Affected by this issue is the function doSystemCmd. The manipulation of the argument usbPartitionName results in command injection.
This vulnerability is known as CVE-2026-24107. It is possible to launch the attack remotely. No exploit is available.