A remote, unauthenticated attacker can gain remote code execution on the the Tenda AC15 router with a specially crafted password parameter for the COOKIE header.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://www.fidusinfosec.com/tenda-ac15-hard-coded-accounts-cve-2018-5768/ | third party advisory |