CVE-2017-9138 - CVE House
Back to Database
Status published High CVE-2017-9138

There is a debug-interface vulnerability on some Tenda routers (FH1202/F1202/F1200:...

Vulnerability Description

There is a debug-interface vulnerability on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). After connecting locally to a router in a wired or wireless manner, one can bypass intended access restrictions by sending shell commands directly and reading their results, or by entering shell commands that change this router's username and password.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-9138

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

f1200 firmware, fh1202 firmware, f1202 firmware
Vulnerable Versions:
0

Timeline

Official Publish: May 21st, 2017
Last Modified: September 17th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.