Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w5qh-gchv-44g2

Опубликовано: 02 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.

Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.

EPSS

Процентиль: 34%
0.00407
Низкий

8.2 High

CVSS3

Дефекты

CWE-922

Связанные уязвимости

CVSS3: 8.2
nvd
больше 1 года назад

Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.

CVSS3: 8.2
fstec
больше 1 года назад

Уязвимость реализации протокола telnet микропрограммного обеспечения маршрутизаторов Tenda RX2 Pro, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 34%
0.00407
Низкий

8.2 High

CVSS3

Дефекты

CWE-922