Tenda RX2 Pro
cpe:2.3:h:tenda:rx2_pro:*:*:*:*:*:*:*, +1 more
- 16.03.30.14
A command injection vulnerability has been identified in the 'setLanCfg' API endpoint of the Tenda RX2 Pro router, running firmware version 16.03.30.14. This vulnerability allows an authorized remote attacker to gain root shell access by sending a crafted web request through the web management portal. The injected command execution is persistent, as the exploitation is saved in the device's configuration.
Exploitation of this vulnerability provides unauthorized root access to the device via a shell.
To reproduce this vulnerability, an authenticated user must send a crafted request to the 'setLanCfg' API endpoint. The injected command will be executed with root privileges and will persist across reboots by being saved in the device's configuration.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.