Denial of Service Vulnerability in Tenda AC6 Router
CVE-2021-40546
4.9MEDIUM
Summary
The Tenda AC6 router is susceptible to a Denial of Service (DoS) condition due to an improperly validated parameter in the device's firmware. If an attacker, having access to the administrator password, sends an excessively long string to the 'wifiPwd_5G' parameter through the /goform/setWifi interface, it can lead to a device crash, rendering the router temporarily unusable. This vulnerability can be exploited to significantly disrupt network services, emphasizing the importance of safeguarding administrator credentials and promptly updating firmware.
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved