S4E just found a high [ai] pa ssl inspection control
medium·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-40843 Scanner

CVE-2022-40843 scanner - Authentication Bypass vulnerability in Tenda AC1200 V-W15Ev2

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-40843
4.9
CVSS

The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router login page to be bypassed. This leads to authenticated attackers having the ability to read the routers syslog.log file which contains the MD5 password of the Administrator's user account.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

The Tenda AC1200 V-W15Ev2 is a dual-band Wi-Fi router designed for home and small office use. It offers high-speed wireless connectivity, supporting the 802.11ac standard for improved coverage and performance. The router is equipped with multiple LAN ports for wired connections and features both local and remote management capabilities. It is widely used for its affordability and feature set, providing users with a stable internet connection for various online activities.

The Authentication Bypass vulnerability in the Tenda AC1200 V-W15Ev2 router arises due to improper session management and authorization checks. This flaw allows unauthenticated attackers to bypass the router's login page, enabling access to sensitive information, such as the MD5 hash of the administrator's password. This issue affects the local web management interface and the remote management console, posing a significant security risk.

This vulnerability is specifically due to the router not validating user sessions correctly or performing inadequate authorization checks for certain actions or resource access. An attacker can exploit this by crafting a request to the router's management interface, bypassing authentication mechanisms to gain unauthorized access. This access can lead to the reading of critical configuration files or system logs, containing sensitive data including the administrator's hashed password.

Exploitation of this vulnerability could lead to unauthorized configuration changes, network compromise, and access to sensitive information. This might allow attackers to alter the router's settings, redirect traffic, or gain further access to the network's internal resources. Such a breach could compromise the security of all devices connected to the network and potentially expose personal or business data.

Joining the S4E platform empowers users with the tools to detect vulnerabilities like the Authentication Bypass in Tenda AC1200 V-W15Ev2. Our comprehensive security scanning solutions offer detailed insights, enabling you to identify and rectify security weaknesses effectively. With our service, you benefit from continuous monitoring, expert support, and actionable guidance to enhance your cybersecurity posture and protect your digital assets against emerging threats.

 

References

Solution Advice
  1. Immediately update the firmware of the Tenda AC1200 V-W15Ev2 router to the latest version provided by the manufacturer.
  2. Regularly check for and apply updates to ensure the router's software remains secure.
  3. Review and strengthen the router's access control settings, including the use of strong, unique passwords for administrative accounts.
  4. Enable network encryption and change default settings to reduce the risk of unauthorized access.
  5. Consider implementing additional network security measures, such as firewalls and intrusion detection systems, to further protect against external threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.