PoC Index

CVE-2019-16213

HIGH 9.0EPSS 2.9%

Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted string, an attacker could modify the device name of an attached PLC adapter to inject and execute arbitrary commands on the system with root privileges.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
2.94% chance of exploitation in the next 30 days, 86th percentile
Published
2020-06-25
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related