Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a…
mitre·CWE-425·Published 2021-01-01
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either a ? character must be placed after the RouterCfm.cfg filename, or that the HTTP request headers must be unusual, but it is not known why these are relevant to the device's HTTP response behavior.
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either a ? character must be placed after the RouterCfm.cfg filename, or that the HTTP request headers must be unusual, but it is not known why these are relevant to the device's HTTP response behavior.
Los dispositivos Tenda N300 F3 versión 12.01.01.48, permiten a atacantes remotos obtener información confidencial (posiblemente incluyendo una línea http_passwd) por medio de una petición directa de cgi-bin/DownloadCfg/RouterCfm.cfg, un problema relacionado con CVE-2017-14942. NOTA: el reporte de vulnerabilidad puede sugerir que un caracter ? debe ser colocado después del nombre del archivo RouterCfm.cfg, o que los encabezados de la petición HTTP deben ser inusuales, pero no se sabe por qué son relevantes para el comportamiento de la respuesta HTTP del dispositivo.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 2.0 | Primary | NVD | 3.3 | 6.5 | 2.9 | AV:A/AC:L/Au:N/C:P/I:N/A:N |
| 3.1 | Primary | cve.org | 9.6 | — | — | CVSS:3.1/AC:L/AV:A/A:H/C:H/I:H/PR:N/S:C/UI:N |
| 3.1 | Primary | cve.org | 9.6 | — | — | CVSS:3.1/AC:L/AV:A/A:H/C:H/I:H/PR:N/S:C/UI:N |
| 3.1 | Primary | NVD | 6.5 | 2.8 | 3.6 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | Secondary | NVD | 9.6 | 2.8 | 6.0 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |