Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w5qh-gchv-44g2

Опубликовано: 02 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.

Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.

EPSS

Процентиль: 42%
0.00204
Низкий

8.2 High

CVSS3

Дефекты

CWE-922

Связанные уязвимости

CVSS3: 8.2
nvd
9 месяцев назад

Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.

CVSS3: 8.2
fstec
9 месяцев назад

Уязвимость реализации протокола telnet микропрограммного обеспечения маршрутизаторов Tenda RX2 Pro, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 42%
0.00204
Низкий

8.2 High

CVSS3

Дефекты

CWE-922