CVE-2018-5768

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
20/03/2018
Last modified:
18/04/2018

Description

A remote, unauthenticated attacker can gain remote code execution on the the Tenda AC15 router with a specially crafted password parameter for the COOKIE header.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tendacn:ac15_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tendacn:ac15:-:*:*:*:*:*:*:*