CVE-2014-5246
high · 10The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access by setting the admin:language cookie to zh-cn.
10
CVSS
12.5%
EPSS (exploit prob.)
96th
EPSS percentile
2014-08-22
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-264
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| tenda | a5s_firmware | 3.02.05_cn |
| tenda | a5s | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/show/osvdb/110146
- http://packetstormsecurity.com/files/127905/Tenda-A5s-Router-Authentication-Bypass.html
- http://www.exploit-db.com/exploits/34361
- http://www.securityfocus.com/bid/69267
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95337
- http://osvdb.org/show/osvdb/110146
- http://packetstormsecurity.com/files/127905/Tenda-A5s-Router-Authentication-Bypass.html
- http://www.exploit-db.com/exploits/34361
- http://www.securityfocus.com/bid/69267
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95337
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2014-5246