CVE-2020-28095

HIGH

Tenda Ac6 Firmware - Infinite Loop

Title source: rule
STIX 2.1

Description

On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0030
EPSS Percentile 52.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-835
Status published
Products (1)
tenda/ac6_firmware 15.03.06.51
Published Dec 30, 2020
Tracked Since Feb 18, 2026