CVE-2024-46450

Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attackers to bypass authentication via a crafted web request.
References
Link Resource
https://pastebin.com/BXxTqsZk Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ac6_firmware:15.03.06.50:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac6:2.0:*:*:*:*:*:*:*

History

07 Jul 2025, 16:40

Type Values Removed Values Added
First Time Tenda ac6 Firmware
Tenda ac6
CPE cpe:2.3:h:tenda:ac1200:ac6:2.0:*:*:*:*:*:*
cpe:2.3:o:tenda:ac1200_firmware:15.03.06.50:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac6_firmware:15.03.06.50:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac6:2.0:*:*:*:*:*:*:*

07 Jul 2025, 16:22

Type Values Removed Values Added
CPE cpe:2.3:h:tenda:ac1200:ac6:2.0:*:*:*:*:*:*
cpe:2.3:o:tenda:ac1200_firmware:15.03.06.50:*:*:*:*:*:*:*
References () https://pastebin.com/BXxTqsZk - () https://pastebin.com/BXxTqsZk - Third Party Advisory
First Time Tenda ac1200
Tenda
Tenda ac1200 Firmware

03 Feb 2025, 21:15

Type Values Removed Values Added
CWE CWE-862
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
Summary
  • (es) El control de acceso incorrecto en el enrutador WiFi de doble banda inteligente Tenda AC1200 modelo AC6 v2.0 Firmware v15.03.06.50 permite a los atacantes omitir la autenticación a través de una solicitud web manipulada específicamente.

16 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-16 22:15

Updated : 2025-07-07 16:40


NVD link : CVE-2024-46450

Mitre link : CVE-2024-46450

CVE.ORG link : CVE-2024-46450


JSON object : View

Products Affected

tenda

  • ac6_firmware
  • ac6
CWE
CWE-862

Missing Authorization