CVE-2014-5246
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
22/08/2014
Last modified:
12/04/2025
Description
The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access by setting the admin:language cookie to zh-cn.
Impact
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:tenda:a5s_firmware:3.02.05_cn:*:*:*:*:*:*:* | ||
cpe:2.3:h:tenda:a5s:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://osvdb.org/show/osvdb/110146
- http://packetstormsecurity.com/files/127905/Tenda-A5s-Router-Authentication-Bypass.html
- http://www.exploit-db.com/exploits/34361
- http://www.securityfocus.com/bid/69267
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95337
- http://osvdb.org/show/osvdb/110146
- http://packetstormsecurity.com/files/127905/Tenda-A5s-Router-Authentication-Bypass.html
- http://www.exploit-db.com/exploits/34361
- http://www.securityfocus.com/bid/69267
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95337