A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation causes use of hard-coded cryptographic key
.
It is possible to initiate the attack remotely.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Tenda 4g03_Pro_Firmware
cpe:2.3:o:tenda:4g03_pro_firmware:04.03.01.53:*:*:*:*:*:*:*
|
— | — |
|
Tenda 4g03_Pro
cpe:2.3:h:tenda:4g03_pro:1.0:*:*:*:*:*:*:*
|
— | — |