Skip to content
COOEY

EXPOSURES › CVE-2021-44971

CVE-2021-44971

CRITICAL
DETAIL
SourceNVD · cve Published2022-01-28 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-44971 ↗
⚡ RCE SHAME 50/100 rce

Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
CVE-2021-44971 represents a critical authentication bypass vulnerability in Tenda devices, enabling attackers to obtain sensitive information and execute remote code execution (RCE) when combined with
cooey ↗ severe-fallout -0.90
Critical vulnerability disclosure
"Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE."
www.techradar.com ↗ severe-fallout -0.80
Critical security backdoor
"These popular Tenda routers have an unpatched security backdoor which could give hackers access"
app.opencve.io ↗ severe-fallout +0.00
Neutral database listing
www.cvefind.com ↗ severe-fallout +0.00
Neutral database listing
SentinelOne ↗ severe-fallout +0.00
Neutral database listing
cve.akaoma.com ↗ severe-fallout +0.00
Neutral database listing
CISA ↗ severe-fallout +0.00
Neutral advisory page
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.