Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.
The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.
Link | Tags |
---|---|
http://tenda.com | vendor advisory |
http://ac15v10.com | broken link url repurposed |
https://github.com/21Gun5/my_cve/blob/main/tenda/bypass_auth.md | broken link |