CVE-2020-28095

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/12/2020
Last modified:
07/07/2025

Description

On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tenda:ac6_firmware:15.03.06.51:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac6:2.0:*:*:*:*:*:*:*