CVE-2022-36552Files or Directories Accessible to External Parties in AC6 Firmware

Severity
7.5HIGHNVD
EPSS
0.4%
top 40.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 30
Latest updateAug 31

Description

Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDtendacn/ac6_firmware02.03.01.114

🔴Vulnerability Details

2
GHSA
GHSA-crh4-w845-25fv: Tenda AC6(AC1200) v52022-08-31
CVEList
CVE-2022-36552: Tenda AC6(AC1200) v52022-08-30
CVE-2022-36552 — Tendacn AC6 Firmware vulnerability | cvebase