Remote Code Execution Vulnerability in Tenda AC1200 Router
CVE-2020-28095

7.5HIGH

Key Information:

Vendor
Tenda
Vendor
CVE Published:
30 December 2020

Summary

A significant vulnerability has been discovered in the Tenda AC1200 (Model AC6) router, specifically in version 15.03.06.51_multi. A malicious actor can exploit this vulnerability by sending a large HTTP POST request to the router's change password API. This action triggers the router to crash, resulting in an infinite boot loop. Users of affected devices should take immediate steps to mitigate this risk and consider applying any available firmware updates.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.