Описание
A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation causes use of hard-coded cryptographic key . It is possible to initiate the attack remotely.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Permissions RequiredVDB Entry
- Product
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:tenda:4g03_pro_firmware:04.03.01.53:*:*:*:*:*:*:*
cpe:2.3:h:tenda:4g03_pro:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 37%
0.00435
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-320
Связанные уязвимости
CVSS3: 5.3
github
5 месяцев назад
A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation causes use of hard-coded cryptographic key . It is possible to initiate the attack remotely.
EPSS
Процентиль: 37%
0.00435
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-320