EXPOSURES › CVE-2021-44971
CVE-2021-44971
CRITICAL
DETAIL
SourceNVD · cve
Published2022-01-28
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-44971 ↗
⚡ RCE
SHAME 50/100
rce
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.80
CVE-2021-44971 represents a critical authentication bypass vulnerability in Tenda devices, enabling attackers to obtain sensitive information and execute remote code execution (RCE) when combined with
Critical vulnerability disclosure
"Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE."
Critical security backdoor
"These popular Tenda routers have an unpatched security backdoor which could give hackers access"
Neutral database listing
Neutral database listing
Neutral database listing
Neutral database listing
Neutral advisory page
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.