Tenda AC1200 Smart Dual-Band WiFi Router Model AC6
cpe:2.3:h:tenda:ac1200:*:*:*:*:*:*:*, +1 more
- 15.03.06.50
An authentication bypass vulnerability has been identified in the Tenda AC1200 Smart Dual-Band WiFi Router, specifically in Model AC6 v2.0 running Firmware v15.03.06.50. This vulnerability arises from incorrect access control, allowing attackers to bypass authentication by sending a crafted web request. Once authenticated, attackers could potentially change router configurations or exploit other vulnerabilities.
Exploitation of this vulnerability allows for authentication bypass, enabling unauthorized access to the router's administrative functions. This could lead to unauthorized changes in router settings or the exploitation of additional vulnerabilities within the device.
To reproduce this vulnerability, intercept a login request to the router using a tool like Burp Suite. The request will include the username and password. By changing the username and password values, it is possible to bypass authentication and gain access to the router.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.