vendor:
F3
by:
@h454nsec
6.5
CVSS
MEDIUM
Malformed HTTP Request Header Processing
20
CWE
Product Name: F3
Affected Version From: All
Affected Version To: All
Patch Exists: YES
Related CWE: CVE-2020-35391
CPE: h:tenda:f3
Platforms Tested: F3v3.0 Firmware
2023
Tenda N300 F3 12.01.01.48 – Malformed HTTP Request Header Processing
Tenda N300 F3 12.01.01.48 is vulnerable to a malformed HTTP request header processing vulnerability. An attacker can exploit this vulnerability by sending a specially crafted HTTP request header to the vulnerable device. This will allow the attacker to gain access to the device and decode the password.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update their devices to the latest version.