PT-2021-11759 · Tenda · Tenda N300 F3
Published
2021-01-01
·
Updated
2024-09-21
·
CVE-2020-35391
CVSS v3.1
9.6
Critical
| Vector | AC:L/AV:A/A:H/C:H/I:H/PR:N/S:C/UI:N |
Name of the Vulnerable Software and Affected Versions:
Tenda N300 F3 version 12.01.01.48
Description:
The issue allows remote attackers to obtain sensitive information, possibly including an http passwd line, via a direct request for "cgi-bin/DownloadCfg/RouterCfm.cfg". The vulnerability may require a specific character, such as ?, to be placed after the RouterCfm.cfg filename, or unusual HTTP request headers, although the reason for this is not clear.
Recommendations:
For Tenda N300 F3 version 12.01.01.48, as a temporary workaround, consider restricting access to the "cgi-bin/DownloadCfg/RouterCfm.cfg" endpoint until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tenda N300 F3