First published: Tue Nov 15 2022(Updated: )
The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router login page to be bypassed. This leads to authenticated attackers having the ability to read the routers syslog.log file which contains the MD5 password of the Administrator's user account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda W15e Firmware | =15.11.0.10\(1576\) | |
Tenda AC1200 V-W15Ev2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-40843 is considered high due to improper authorization allowing sensitive data exposure.
To fix CVE-2022-40843, update the Tenda W15e firmware to the latest available version that addresses the vulnerability.
CVE-2022-40843 affects Tenda AC1200 V-W15Ev2 routers running firmware version 15.11.0.10(1576).
The consequences of CVE-2022-40843 include potential unauthorized access to the router's log file, which may contain sensitive information such as passwords.
Authenticated attackers with access to the router could exploit CVE-2022-40843 to bypass the login page and access sensitive data.