CVE-2017-9138: Buffer Overflow
Published May 21, 2017
·Updated
There is a debug-interface vulnerability on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). After connecting locally to a router in a wired or wireless manner, one can bypass intended access restrictions by sending shell commands directly and reading their results, or by entering shell commands that change this router's username and password.
Affected Software
6 affected components
Tendacn F1200 Firmware<=1.2.0.19
Tendacn F1200
Tendacn Fh1202 Firmware<=1.2.0.19
Tendacn Fh1202
Tendacn F1202 Firmware<=1.2.0.19
Tendacn F1202
Event History
May 21, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description