PT-2020-15878 · Tenda · Tenda Ac18 Router
Published
2020-09-04
·
Updated
2022-11-07
·
CVE-2020-24987
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tenda AC18 Router versions through V15.03.05.05 EN
Tenda AC18 Router versions through V15.03.05.19(6318) CN
Description
The issue is related to incorrect authentication handling of the
logincheck() function in the /usr/lib/lua/ngx authserver/ngx wdas.lua file. This can lead to remote code execution if the administrator UI Interface is set to "radius".Recommendations
For Tenda AC18 Router versions through V15.03.05.05 EN, consider disabling the
logincheck() function until a patch is available.
For Tenda AC18 Router versions through V15.03.05.19(6318) CN, restrict access to the /usr/lib/lua/ngx authserver/ngx wdas.lua file to minimize the risk of exploitation.
As a temporary workaround, avoid using the "radius" setting for the administrator UI Interface until the issue is resolved.Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tenda Ac18 Router