Remote Command Execution Vulnerability in Tenda PA6 Wi-Fi Powerline Extender
CVE-2019-16213
8.8HIGH
What is CVE-2019-16213?
The Tenda PA6 Wi-Fi Powerline extender version 1.0.1.21 is susceptible to a remote command execution vulnerability. This flaw allows authenticated attackers to inject and execute arbitrary commands on the device by sending a specially crafted string. By manipulating the device name of an attached PLC adapter, attackers can exploit this vulnerability to gain root-level access, potentially compromising the device and the network it connects to. This highlights critical concerns in the security of IoT devices, underlining the necessity for enhanced protective measures.