CVE-2014-5246

Tenda A5s Firmware 3.02.05_CN - Unauthenticated Authentication Bypass via admin:language Cookie

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-5246. PoCs published by zixian.

AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Tenda A5s routers by manipulating the 'admin:language' cookie to gain unauthorized access to the admin interface.

Description

The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access by setting the admin:language cookie to zh-cn.

Exploits (1)

exploitdb WORKING POC
by zixian · textwebappshardware
https://www.exploit-db.com/exploits/34361

This exploit demonstrates an authentication bypass vulnerability in Tenda A5s routers by manipulating the 'admin:language' cookie to gain unauthorized access to the admin interface.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Tenda A5s Router V3.02.05_CN
No auth needed
Prerequisites: Access to the router's web interface · JavaScript execution capability in the browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/34361
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/95337
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/110146
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/69267

Scores

EPSS 0.1249
EPSS Percentile 95.7%

Details

CWE
CWE-264
Status published
Products (2)
tenda/a5s
tenda/a5s_firmware 3.02.05_cn
Published Aug 22, 2014
Tracked Since Feb 18, 2026