PT-2026-47437 · Tenda · F451
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda F451 versions 1.0.0.7 through 1.0.0.9
Description
A security flaw in the Web Management Interface allows remote exploitation via OS command injection. The issue exists within the
formWriteFacMac() function located in the /goform/WriteFacMac file. An attacker can trigger this by manipulating the mac argument.Recommendations
For versions 1.0.0.7 through 1.0.0.9, disable remote management.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
F451