Description
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path attacker to obtain sensitive authentication material.
Problem types
CWE-319 Cleartext Transmission of Sensitive Information
Product status
Any version
Credits
Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.
References
www.tendacn.com/product/AC7
www.vulncheck.com/...in-credentials-without-https-protection