CVE-2018-5770: Critical severity Tendacn Ac15 Firmware vulnerability
Published Mar 20, 2018
·Updated
An issue was discovered on Tenda AC15 devices. A remote, unauthenticated attacker can make a request to /goform/telnet, creating a telnetd service on the device. This service is password protected; however, several default accounts exist on the device that are root accounts, which can be used to log in.
Affected Software
4 affected components
Tendacn Ac15 Firmware
Tendacn Ac15
All of the following
Tendacn Ac15 Firmware
Tendacn Ac15
Event History
Mar 20, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue on Tenda AC15 devices?
The vulnerability ID for this issue on Tenda AC15 devices is CVE-2018-5770.
2
What is the severity rating of CVE-2018-5770?
The severity rating of CVE-2018-5770 is critical with a rating of 9.8.
3
How can an attacker exploit CVE-2018-5770?
An attacker can exploit CVE-2018-5770 by making a request to /goform/telnet, creating a telnetd service on the device.
4
Are Tenda AC15 devices affected by CVE-2018-5770?
Yes, Tenda AC15 devices are affected by CVE-2018-5770.
5
Is there a fix for CVE-2018-5770?
Currently, there is no fix available for CVE-2018-5770. It is recommended to disable telnet and use more secure alternatives.