Vulnerabilities > CVE-2022-36552 - Files or Directories Accessible to External Parties vulnerability in Tendacn AC6 Firmware

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
tendacn
CWE-552

Summary

Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.

Vulnerable Configurations

Part Description Count
OS
Tendacn
1
Hardware
Tendacn
1