Description
There is a debug-interface vulnerability on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). After connecting locally to a router in a wired or wireless manner, one can bypass intended access restrictions by sending shell commands directly and reading their results, or by entering shell commands that change this router's username and password.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-18076 | There is a debug-interface vulnerability on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). After connecting locally to a router in a wired or wireless manner, one can bypass intended access restrictions by sending shell commands directly and reading their results, or by entering shell commands that change this router's username and password. |
References
| Link | Providers |
|---|---|
| http://www.tendacn.com/en/2017.html |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T02:53:16.805Z
Reserved: 2017-05-21T00:00:00.000Z
Link: CVE-2017-9138
No data.
Status : Modified
Published: 2017-05-21T22:29:00.180
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-9138
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD