First published: Wed Dec 30 2020(Updated: )
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda AC1200 Firmware | =15.03.06.51_multi | |
Tenda AC1200 V-W15Ev2 | =ac6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28095 is considered a high severity vulnerability due to its ability to crash the router and cause an infinite boot loop.
To fix CVE-2020-28095, update the firmware of the Tenda AC1200 to a version that addresses this vulnerability.
The vulnerability CVE-2020-28095 affects Tenda AC1200 devices running firmware version 15.03.06.51_multi.
The impact of CVE-2020-28095 is that a large HTTP POST request can crash the router, causing it to enter an infinite boot loop.
The Tenda AC6 model is not directly affected by CVE-2020-28095 as it pertains to the firmware version of the AC1200.