CVE-2020-35391
Severity CVSS v4.0:
Pending analysis
Type:
CWE-425
Direct Request ('Forced Browsing')
Publication date:
01/01/2021
Last modified:
07/11/2023
Description
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either a ? character must be placed after the RouterCfm.cfg filename, or that the HTTP request headers must be unusual, but it is not known why these are relevant to the device's HTTP response behavior.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tenda:f3_firmware:12.01.01.48:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tenda:f3:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



