Tenda W18E
cpe:2.3:h:tenda:w18e:*:*:*:*:*:*:*
- V16.01.0.8(1625)
An incorrect access control vulnerability has been identified in the Tenda W18E router, specifically in version 16.01.0.8(1625). This vulnerability allows an unauthenticated remote attacker to change the administrator password through the web management portal. The issue arises by sending a specially crafted HTTP POST request to the setLoginPassword function, effectively bypassing the authentication mechanism.
Exploitation of this vulnerability allows for unauthorized password changes, potentially leading to unauthorized administrative access on the device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.