Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs because the "formSetDebugCfg" function executes glibc's system function with untrusted input.
Conclusion & alert: CVE-2021-27691 is rated High Risk (78.4/100): CVSS Critical severity, with high exploitation likelihood (EPSS 25.18%, 98th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +20.79% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 4.40% | 25.18% | +20.79% |
| 2 | 2025-11-21 | 3.36% | 4.40% | +1.04% |
| 3 | 2025-11-18 | — | 3.36% | — |
Full EPSS history (15 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 10.0 | 2.0 | HIGH |
|
10.0 | 10.0 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| tendacn | g0_firmware | 15.11.0.5\(5876\)_cn | cpe:2.3:o:tendacn:g0_firmware:15.11.0.5\(5876\)_cn:*:*:*:*:*:*:* |
| tendacn | g0_firmware | 15.11.0.6\(9039\)_cn | cpe:2.3:o:tendacn:g0_firmware:15.11.0.6\(9039\)_cn:*:*:*:*:*:*:* |
| tendacn | g1_firmware | 15.11.0.16\(9024\)_cn | cpe:2.3:o:tendacn:g1_firmware:15.11.0.16\(9024\)_cn:*:*:*:*:*:*:* |
| tendacn | g1_firmware | 15.11.0.17\(9502\)_cn | cpe:2.3:o:tendacn:g1_firmware:15.11.0.17\(9502\)_cn:*:*:*:*:*:*:* |
| tendacn | g3_firmware | 15.11.0.16\(9024\)_cn | cpe:2.3:o:tendacn:g3_firmware:15.11.0.16\(9024\)_cn:*:*:*:*:*:*:* |
| tendacn | g3_firmware | 15.11.0.17\(9502\)_cn | cpe:2.3:o:tendacn:g3_firmware:15.11.0.17\(9502\)_cn:*:*:*:*:*:*:* |