Vulnerability Details CVE-2021-47802
Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers to retrieve router configuration files. Attackers can send a request to /goform/getimage endpoint to download configuration data including admin credentials without authentication.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.6%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2021-47802
-
-
-
cpe:2.3:o:tenda:d151_firmware:-
-
cpe:2.3:o:tenda:d301_firmware:-