Denial of Service Vulnerability in Tenda AC6 Router
CVE-2021-40546

4.9MEDIUM

Key Information:

Vendor
Tenda
Vendor
CVE Published:
5 September 2023

Summary

The Tenda AC6 router is susceptible to a Denial of Service (DoS) condition due to an improperly validated parameter in the device's firmware. If an attacker, having access to the administrator password, sends an excessively long string to the 'wifiPwd_5G' parameter through the /goform/setWifi interface, it can lead to a device crash, rendering the router temporarily unusable. This vulnerability can be exploited to significantly disrupt network services, emphasizing the importance of safeguarding administrator credentials and promptly updating firmware.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.