← العودة للجدول
CVE-2020-35391
CVE-2020-35391 — Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive inf
📅 2021-01-01
🔴 Critical 🔥 No NVD Exploit Network CVSS 9.6

📋 الوصف الكامل

Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either a ? character must be placed after the RouterCfm.cfg filename, or that the HTTP request headers must be unusual, but it

💻 الأنظمة المتأثرة

Tenda N300 F3

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2020-35391

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2020-35391 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←