Cleartext Transmission Vulnerability in Tenda N301 Router Firmware
CVE-2023-29680
5.7MEDIUM
Summary
The Tenda N301 Router's firmware has a vulnerability that exposes sensitive information due to the use of cleartext transmission in cookie settings. This flaw enables an authenticated attacker on the local area network (LAN) or wireless local area network (WLAN) to intercept communications with the router, allowing them to capture the ecosystem password. Such exploitation can lead to unauthorized access to the router and connected devices, posing a significant security risk to users. It is essential for users to update their firmware to mitigate this vulnerability.
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved