CVE-2021-40546: Medium severity tenda ac6 firmware vulnerability
Tenda AC6 USAC6V4.0RTLV02.03.01.26cn.bin allows attackers (who have the administrator password) to cause a denial of service (device crash) via a long string in the wifiPwd5G parameter to /goform/setWifi.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-40546?
CVE-2021-40546 is a vulnerability in Tenda AC6 US_AC6V4.0RTL_V02.03.01.26_cn.bin that allows attackers with the administrator password to cause a denial of service (device crash) by sending a long string in the wifiPwd_5G parameter to /goform/setWifi.
How severe is CVE-2021-40546?
CVE-2021-40546 has a severity rating of 4.9 out of 10, indicating a medium severity.
How can attackers exploit CVE-2021-40546?
Attackers can exploit CVE-2021-40546 by using the administrator password to send a long string in the wifiPwd_5G parameter to /goform/setWifi, causing a denial of service and crashing the device.
Is Tenda AC6 firmware version 02.03.01.26 affected by CVE-2021-40546?
Yes, Tenda AC6 firmware version 02.03.01.26 is affected by CVE-2021-40546.
How can I fix CVE-2021-40546?
To fix CVE-2021-40546, it is recommended to update to a patched version of the firmware provided by Tenda.