Tenda W18E
cpe:2.3:h:tenda:w18e:*:*:*:*:*:*:*
- V16.01.0.8(1625)
A vulnerability allowing sensitive information disclosure has been identified in the Tenda W18E router, specifically in version V16.01.0.8(1625). The issue resides in the web management portal, where an unauthenticated remote attacker can retrieve confidential configuration details. This includes the WiFi SSID, WiFi password, and base64-encoded administrator credentials. The vulnerability is exploited by sending a specially crafted HTTP POST request to the 'getQuickCfgWifiAndLogin' function, which bypasses authentication checks.
Exploitation of this vulnerability allows for unauthorized access to sensitive configuration information, including WiFi credentials and administrator login details.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.