Impact
Tenda routers running firmware version V02.03.01.26_cn are affected by an incorrect access control flaw that allows any unauthenticated user to request the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint. This endpoint returns the entire configuration file, which contains plaintext administrator credentials. The flaw is a classic example of CWE‑284, Missing Authorization, and enables attackers to obtain sensitive information that could be leveraged to gain remote administrative control of the device.
Affected Systems
The vulnerability applies to Tenda W15E routers with firmware V02.03.01.26_cn. No other vendor or product variants are listed in the advisory; the security impact is limited to this specific model and firmware revision.
Risk and Exploitability
The CVSS base score is 7.5, indicating a high severity risk. EPSS indicates a probability of exploitation of less than 1%, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local network attacker interacting with the web interface, though any scenario that exposes the router’s management interface to the internet could increase risk. The vulnerability allows threat actors to download configuration files and extract privileged credentials, potentially enabling full remote control of the device.
OpenCVE Enrichment