7.8
CVE-2020-28095
- EPSS 0.3%
- Veröffentlicht 30.12.2020 21:15:12
- Zuletzt bearbeitet 07.07.2025 17:21:03
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tenda ≫ Ac6 Firmware Version15.03.06.51
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.499 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| nvd@nist.gov | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.