Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7x7v-wrpx-628j

Опубликовано: 21 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 0.9
CVSS3: 6.4

Описание

A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized.

A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized.

EPSS

Процентиль: 2%
0.00014
Низкий

0.9 Low

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-259

Связанные уязвимости

CVSS3: 1.9
nvd
3 месяца назад

A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized.

CVSS3: 1.9
fstec
3 месяца назад

Уязвимость административного интерфейса микропрограммного обеспечения маршрутизаторов Tenda F1202, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 2%
0.00014
Низкий

0.9 Low

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-259