CVE-2021-44971: Command Injection
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20multi?AC5V1.0 Firmware V15.03.06.48multi and so on. an attacker can obtain sensitive information, and even combine it with authenticated command injection to implement RCE.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this authentication bypass vulnerability?
The vulnerability ID for this authentication bypass vulnerability is CVE-2021-44971.
Which Tenda devices are affected by this authentication bypass vulnerability?
Multiple Tenda devices, such as AC15V1.0 Firmware V15.03.05.20_multi and AC5V1.0 Firmware V15.03.06.48_multi, are affected by this authentication bypass vulnerability.
What is the severity rating of CVE-2021-44971?
The severity rating of CVE-2021-44971 is critical with a score of 9.8.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability to obtain sensitive information, and even combine it with authenticated command injection to implement Remote Code Execution (RCE).
Is there a fix available for this vulnerability?
Please refer to the references provided for information on available fixes or patches for this vulnerability.