CVE-2019-16213: OS Command Injection
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted string, an attacker could modify the device name of an attached PLC adapter to inject and execute arbitrary commands on the system with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-16213?
CVE-2019-16213 is a vulnerability in the Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 that could allow a remote authenticated attacker to execute arbitrary commands on the system.
What is the severity of CVE-2019-16213?
CVE-2019-16213 has a severity rating of 8.8 (Critical).
How does the vulnerability in the Tenda PA6 Wi-Fi Powerline extender occur?
The vulnerability in the Tenda PA6 Wi-Fi Powerline extender occurs when a remote authenticated attacker sends a specially crafted string to modify the device name of an attached PLC adapter, allowing them to inject and execute arbitrary commands on the system.
Which version of Tendacn Pa6 Firmware is affected by CVE-2019-16213?
Tendacn Pa6 Firmware version 1.0.1.21 is affected by CVE-2019-16213.
Is Tendacn Pa6 affected by CVE-2019-16213?
No, Tendacn Pa6 is not affected by CVE-2019-16213.