A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47multi allows remote attackers to inject arbitrary web script or HTML via the Wifi Name parameter.
On Tenda AC1200 (Model AC6) 15.03.06.51multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.
On Tenda AC1200 (Model AC6) 15.03.06.51multi devices, the default settings for the router speed test contain links to download malware named elive or CNKI E-Learning.
On Tenda AC1200 (Model AC6) 15.03.06.51multi devices, admin, support, user, and nobody have a password of 1234.