Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w55r-jjxw-gxrx

Опубликовано: 06 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8.

  • The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key).
  • After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration.
  • It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password.

A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor

The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8.

  • The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key).
  • After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration.
  • It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password.

A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor

EPSS

Процентиль: 74%
0.01616
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
28 дней назад

The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration. - It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password. A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor

CVSS3: 9.8
fstec
29 дней назад

Уязвимость функции login() микропрограммного обеспечения роутеров Tenda, позволяющая нарушителю получить полный доступ к веб-интерфейсу устройства

EPSS

Процентиль: 74%
0.01616
Низкий

9.8 Critical

CVSS3