Impact
A flaw in the SetRedirectEnable function of Tenda CP3 firmware exposes improper privilege management that allows an attacker to gain elevated privileges on the device. This weakness can be exploited remotely, enabling an attacker to execute privileged actions or compromise the router’s configuration, thereby threatening confidentiality, integrity, and availability of the network. The vulnerability is classified as high severity with a CVSS score of 9.4 and maps to CWE-266 and CWE-269.
Affected Systems
The issue affects Tenda CP3 units running firmware version 27.5.57.101. Users of this specific firmware should verify their device version and apply available updates.
Risk and Exploitability
The CVSS score indicates a critical severity and the EPSS score is not available, which does not diminish the potential for exploitation. The vulnerability is not listed in CISA’s KEV catalog, but remote exploitation is explicitly possible. With remote access to the router’s interface or network traffic, an attacker can manipulate the SetRedirectEnable setting and elevate privileges to compensate for the improper access control, as detailed by the CWE identifiers.
OpenCVE Enrichment