Vulnerability Description
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ac15 Firmware | 15.03.05.20_multi |
| Tenda | Ac15 | 1.0 |
| Tenda | Ac5 Firmware | 15.03.06.48_multi |
| Tenda | Ac5 | 1.0 |
Related Weaknesses (CWE)
References
- http://ac15v10.comBroken LinkURL Repurposed
- http://tenda.comVendor Advisory
- https://github.com/21Gun5/my_cve/blob/main/tenda/bypass_auth.mdBroken Link
- http://ac15v10.comBroken LinkURL Repurposed
- http://tenda.comVendor Advisory
- https://github.com/21Gun5/my_cve/blob/main/tenda/bypass_auth.mdBroken Link
FAQ
What is CVE-2021-44971?
CVE-2021-44971 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, ...
How severe is CVE-2021-44971?
CVE-2021-44971 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-44971?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ac15 Firmware, Tenda Ac15, Tenda Ac5 Firmware, Tenda Ac5.