CVE-2021-47802
7.5Tenda · D151 and D301 Routers
Tenda D151 and D301 routers are vulnerable to an unauthenticated configuration download via the /goform/getimage endpoint, potentially exposing administrative credentials.
Executive summary
A critical vulnerability in Tenda D151 and D301 routers allows unauthenticated remote attackers to download sensitive configuration files and compromise administrative credentials.
Vulnerability
The device suffers from missing authentication for a critical function (CWE-306). By sending a request to the /goform/getimage endpoint, an unauthenticated attacker can retrieve the router configuration, which includes plaintext or easily decodable administrative credentials.
Business impact
Successful exploitation allows an attacker to gain full administrative control over the router. This access can be used to intercept network traffic, modify DNS settings to facilitate man-in-the-middle attacks, or provide a foothold for lateral movement into the internal network. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to the confidentiality and integrity of the entire connected local network.
Remediation
Immediate Action: Review vendor support channels for available firmware updates that address this endpoint security flaw. If no patch is available for specific hardware revisions, retire the hardware or isolate the device from the public-facing internet.
Proactive Monitoring: Inspect network logs for unauthorized GET requests to the /goform/getimage or /goform/telnet endpoints. Flag any internal or external IP addresses attempting to access these administrative paths.
Compensating Controls: Implement an external firewall or Access Control List (ACL) to restrict management access to the router to a known, trusted internal management VLAN only. Disable remote management interfaces on the WAN side immediately.
Exploitation status
Public Exploit Available: Yes, a functional exploit script is available via ExploitDB (EDB-ID 49782).
Analyst recommendation
Due to the ease of exploitation and the critical nature of the exposed administrative credentials, organizations using Tenda D151 or D301 routers must treat this as a priority. If firmware updates are not available, the devices should be removed from the network perimeter immediately to prevent remote compromise. Ensure all administrative interfaces are segmented from public access as a baseline security requirement.
More Tenda CVEs
Sources
Originally found and disclosed by BenChaliah, per the CVE Program record.
- ExploitDB-49782 Exploit / PoC
- Tenda Official Vendor Homepage
- VulnCheck Advisory: Tenda D151 & D301 - Configuration Download Third-party advisory