ID

VAR-201908-2201


TITLE

Tenda W20E V15.11.0.6_CN has command execution vulnerability (CNVD-2019-22867)

Trust: 0.6

sources: CNVD: CNVD-2019-22867

DESCRIPTION

Shenzhen Lucky Tenda Technology Co., Ltd. is one of the first pioneers in China's wireless network field. Tenda W20E V15.11.0.6_CN has a command execution vulnerability, which can be used by an attacker to gain server permissions.

Trust: 0.6

sources: CNVD: CNVD-2019-22867

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-22867

AFFECTED PRODUCTS

vendor:lucky tendamodel:w20e v15.11.0.6 cnscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2019-22867

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2019-22867
value: HIGH

Trust: 0.6

CNVD: CNVD-2019-22867
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:H/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2019-22867

PATCH

title:Tenda W20E firmware version V15.11.0.6_CN has a command execution vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/167623

Trust: 0.6

sources: CNVD: CNVD-2019-22867

EXTERNAL IDS

db:CNVDid:CNVD-2019-22867

Trust: 0.6

sources: CNVD: CNVD-2019-22867

SOURCES

db:CNVDid:CNVD-2019-22867

LAST UPDATE DATE

2022-05-04T09:16:18.817000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-22867date:2019-07-18T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-22867date:2019-08-22T00:00:00