CVE-2017-9138
8.0
Vector
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.1 / Impact: 5.9
Source: NVD
Description
There is a debug-interface vulnerability on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). After connecting locally to a router in a wired or wireless manner, one can bypass intended access restrictions by sending shell commands directly and reading their results, or by entering shell commands that change this router's username and password.
Affected (3)
Products: Tendacn: F1200 Firmware, Fh1202 Firmware, F1202 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.19 |
| Running on/with | Platform Versions |
|---|---|
Tendacn F1200 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.19 |
| Running on/with | Platform Versions |
|---|---|
Tendacn Fh1202 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.0.19 |
| Running on/with | Platform Versions |
|---|---|
Tendacn F1202 | All versions |
References (2)
Timeline
No history available yet.