Improper Authorization in Tenda AC1200 Router by Tenda
CVE-2022-40843

4.9MEDIUM

Key Information:

Vendor
Tenda
Vendor
CVE Published:
15 November 2022

Summary

The Tenda AC1200 V-W15Ev2 router has a significant vulnerability related to improper authorization and session management. This flaw allows authenticated attackers to bypass the router's login page, granting them unauthorized access. Once inside, attackers can read sensitive information within the router's syslog.log file, which contains the MD5 hashed password for the Administrator's account. This vulnerability poses a serious risk to the security and integrity of the router, potentially compromising user data and network security.

References

EPSS Score

8% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.