Impact
An issue in the Tneda W20E firmware version 16.01.0.6(2782) allows a remote attacker to execute arbitrary code by exploiting the url_need_login function. This flaw enables running unintended code on the device, potentially compromising the device’s operation.
Affected Systems
The affected product is the Tneda W20E router running firmware version 16.01.0.6(2782). No other vendors or products are listed as impacted.
Risk and Exploitability
Exploitation appears to be achievable over the network by sending specially crafted HTTP requests to the url_need_login endpoint. Based on the description, the vulnerability could be leveraged to obtain remote code execution, implying a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the lack of mitigation details suggests a significant risk if the device is exposed to the internet.
OpenCVE Enrichment