cecada/Tenda-AC6-Root-Acces

cecada/Tenda-AC6-Root-Acces

Releases0
Stars17
A vuln existss in Tenda AC6 router which allows an attacker to launch a telnet session with root access.

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH7.8 HIGH

On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.

7.2 HIGH6.5 MEDIUM

On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, admin, support, user, and nobody have a password of 1234.

7.5 HIGH5 MEDIUM

On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, the default settings for the router speed test contain links to download malware named elive or CNKI E-Learning.