CVE-2020-28095
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/12/2020
Last modified:
07/07/2025
Description
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tenda:ac6_firmware:15.03.06.51:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:ac6:2.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



