PT-2026-3797 · Tenda · Tenda D301+1

Benchaliah

·

Published

2026-01-21

·

Updated

2026-02-02

·

CVE-2021-47802

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tenda D151 routers (affected versions not specified) Tenda D301 routers (affected versions not specified)
Description Remote attackers can retrieve router configuration files from Tenda D151 and D301 routers without authentication. This is possible by sending a request to the /goform/getimage API endpoint. The configuration data downloaded may include admin credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-47802

Affected Products

Tenda D151
Tenda D301