CVE-2014-5246: Critical severity tenda a5s vulnerability
Published Aug 22, 2014
·Updated
The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05CN allows remote attackers to bypass authentication and gain administrator access by setting the admin:language cookie to zh-cn.
Affected Software
2 affected components
Tenda A5s Firmware=3.02.05_cn
Tenda A5s
Event History
Aug 22, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5246?
CVE-2014-5246 is classified as a high severity vulnerability due to its authentication bypass nature.
2
How do I fix CVE-2014-5246?
To fix CVE-2014-5246, upgrade the Tenda A5s router firmware to a version that patches this vulnerability.
3
What are the potential impacts of CVE-2014-5246?
The potential impacts of CVE-2014-5246 include unauthorized remote access to the router's administration panel.
4
Who is affected by CVE-2014-5246?
Users of the Tenda A5s router running firmware version 3.02.05_CN are affected by CVE-2014-5246.
5
Can CVE-2014-5246 be exploited remotely?
Yes, CVE-2014-5246 can be exploited remotely without authentication.