vendor:
W309R
by:
SANTHO
4,3
CVSS
MEDIUM
Configuration Enumeration
287
CWE
Product Name: W309R
Affected Version From: V5.07.46
Affected Version To: V5.07.46
Patch Exists: YES
Related CWE: N/A
CPE: h:tenda:w309r
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Tenda W309R Configuration Enumeration without Authentication
Tenda Wireless Router W309R doesn't have proper authentication for the web application console. Though the application asks for password, it has poor cookie management which allows a user to login even without providing the password. Application uses cookie value 'admin' to access the private pages which reveals configuration details such as PPoE username, PPoE password, wireless authentication key, details of MAC addresses etc, in the source code.
Mitigation:
Ensure proper authentication is implemented for the web application console.