Tenda WH450 Command Injection Vulnerability in HTTP Request Handler
Vulnerability
A command injection vulnerability has been identified in the Tenda WH450 router, specifically in the firmware version 1.0.0.18. The issue arises within the HTTP request handler for the '/goform/CheckTools' endpoint. This vulnerability can be exploited remotely by unauthenticated attackers, allowing them to execute arbitrary commands on the router. The exploitation involves manipulating the 'ipaddress' parameter with excessive data lengths, which triggers the command injection.
Impact
Exploitation of this vulnerability allows for arbitrary code execution on the affected router.
Reproduction
To reproduce this vulnerability, send a GET request to the '/goform/CheckTools' endpoint with the 'ipaddress' parameter. Include a payload that appends a command to be executed, such as a command to read the '/etc/passwd' file and write it to a temporary location.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
