Tenda AC15 v15.03.05.18_multi) issues an authentication...
Critical severity
Unreviewed
Published
Nov 12, 2025
to the GitHub Advisory Database
•
Updated Nov 13, 2025
Description
Published by the National Vulnerability Database
Nov 12, 2025
Published to the GitHub Advisory Database
Nov 12, 2025
Last updated
Nov 13, 2025
Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to run JS in a victim browser can steal the cookie and replay it to access protected resources.
References