First published: Tue Mar 20 2018(Updated: )
An issue was discovered on Tenda AC15 devices. A remote, unauthenticated attacker can make a request to /goform/telnet, creating a telnetd service on the device. This service is password protected; however, several default accounts exist on the device that are root accounts, which can be used to log in.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tendacn Ac15 Firmware | ||
Tendacn Ac15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue on Tenda AC15 devices is CVE-2018-5770.
The severity rating of CVE-2018-5770 is critical with a rating of 9.8.
An attacker can exploit CVE-2018-5770 by making a request to /goform/telnet, creating a telnetd service on the device.
Yes, Tenda AC15 devices are affected by CVE-2018-5770.
Currently, there is no fix available for CVE-2018-5770. It is recommended to disable telnet and use more secure alternatives.