A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized.
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Fh1202_firmware | Tenda | 1.2.0.9 (including) | 1.2.0.9 (including) |
| Fh1202_firmware | Tenda | 1.2.0.14 (including) | 1.2.0.14 (including) |
| Fh1202_firmware | Tenda | 1.2.0.20 (including) | 1.2.0.20 (including) |
There are two main variations of a hard-coded password: