PT-2025-1139 · Tenda · Tenda Ac1200 Smart Dual-Band Wifi Router
Ivan Dushkov
·
Published
2025-01-15
·
Updated
2025-07-07
·
CVE-2024-46450
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 version 2.0 Firmware v15.03.06.50
Description
The issue is related to incorrect access control in the Tenda AC1200 Smart Dual-Band WiFi Router, which allows attackers to bypass authentication via a crafted web request. This can enable a remote attacker to gain unauthorized access to the device. The vulnerability is associated with a lack of necessary checks when changing the password.
Recommendations
For Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 version 2.0 Firmware v15.03.06.50, consider disabling remote access to the device until a patch is available. Restrict access to the web interface to minimize the risk of exploitation. Avoid using the device's web interface for critical operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda Ac1200 Smart Dual-Band Wifi Router