VYPR
Unrated severityNVD Advisory· Published Jun 26, 2026· Updated Jun 29, 2026

CVE-2026-38571

CVE-2026-38571

Description

Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticated UART debug console of the Tenda N300 F3 (V603) allow a physically proximate attacker to obtain stored WPA2 credentials in cleartext and to read or write arbitrary memory via the serial console.

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.