Vulnerabilities > CVE-2018-5770 - Insecure Default Initialization of Resource vulnerability in Tendacn Ac15 Firmware

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
tendacn
CWE-1188
critical

Summary

An issue was discovered on Tenda AC15 devices. A remote, unauthenticated attacker can make a request to /goform/telnet, creating a telnetd service on the device. This service is password protected; however, several default accounts exist on the device that are root accounts, which can be used to log in.

Vulnerable Configurations

Part Description Count
OS
Tendacn
1
Hardware
Tendacn
1