PT-2020-15878 · Tenda · Tenda Ac18 Router

Published

2020-09-04

·

Updated

2022-11-07

·

CVE-2020-24987

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda AC18 Router versions through V15.03.05.05 EN Tenda AC18 Router versions through V15.03.05.19(6318) CN
Description The issue is related to incorrect authentication handling of the logincheck() function in the /usr/lib/lua/ngx authserver/ngx wdas.lua file. This can lead to remote code execution if the administrator UI Interface is set to "radius".
Recommendations For Tenda AC18 Router versions through V15.03.05.05 EN, consider disabling the logincheck() function until a patch is available. For Tenda AC18 Router versions through V15.03.05.19(6318) CN, restrict access to the /usr/lib/lua/ngx authserver/ngx wdas.lua file to minimize the risk of exploitation. As a temporary workaround, avoid using the "radius" setting for the administrator UI Interface until the issue is resolved.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2020-24987

Affected Products

Tenda Ac18 Router