CVE-2026-38571

Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticated UART debug console of the Tenda N300 F3 (V603) allow a physically proximate attacker to obtain stored WPA2 credentials in cleartext and to read or write arbitrary memory via the serial console.
CVSS

No CVSS.

Configurations

No configuration.

History

26 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-26 22:16

Updated : 2026-06-26 22:16


NVD link : CVE-2026-38571

Mitre link : CVE-2026-38571

CVE.ORG link : CVE-2026-38571


JSON object : View

Products Affected

No product.

CWE

No CWE.