High severity7.5NVD Advisory· Published Jan 21, 2026· Updated Jun 17, 2026
CVE-2021-47802
CVE-2021-47802
Description
Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers to retrieve router configuration files. Attackers can send a request to /goform/getimage endpoint to download configuration data including admin credentials without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:o:tenda:d151_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:tenda:d301_firmware:-:*:*:*:*:*:*:*
- Shenzhen Tenda Technology Co.,Ltd./Tenda D151 & D301v5Range: -
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/49782nvdExploit
- www.tendacn.com/us/nvdProduct
- www.vulncheck.com/advisories/tenda-d-d-configuration-downloadnvdBroken Link
News mentions
0No linked articles in our index yet.