PT-2021-19554 · Tenda · Tenda Ac5 Ac1200

Chiragh Arora

·

Published

2021-01-24

·

Updated

2025-07-07

·

CVE-2021-3186

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Tenda AC5 AC1200 version V15.03.06.47 multi
Description: A Stored Cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the Wifi Name parameter in the Wifi Settings, specifically in the /main.html endpoint.
Recommendations: For Tenda AC5 AC1200 version V15.03.06.47 multi, avoid using the Wifi Name parameter in the /main.html Wifi Settings until the issue is resolved. As a temporary workaround, consider restricting access to the Wifi Settings page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-3186

Affected Products

Tenda Ac5 Ac1200