Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the firmware image can extract and attempt to crack the root password hash, potentially obtaining administrative access
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://www.tendacn.com/product/download/cp3pro.html | broken link |
https://cybermaya.in/posts/Post-39/ | third party advisory exploit |