PT-2021-11759 · Tenda · Tenda N300 F3

Published

2021-01-01

·

Updated

2024-09-21

·

CVE-2020-35391

CVSS v3.1

9.6

Critical

VectorAC:L/AV:A/A:H/C:H/I:H/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions: Tenda N300 F3 version 12.01.01.48
Description: The issue allows remote attackers to obtain sensitive information, possibly including an http passwd line, via a direct request for "cgi-bin/DownloadCfg/RouterCfm.cfg". The vulnerability may require a specific character, such as ?, to be placed after the RouterCfm.cfg filename, or unusual HTTP request headers, although the reason for this is not clear.
Recommendations: For Tenda N300 F3 version 12.01.01.48, as a temporary workaround, consider restricting access to the "cgi-bin/DownloadCfg/RouterCfm.cfg" endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2020-35391

Affected Products

Tenda N300 F3