CVE-2014-5246: Tenda a5s

High severity, CVSS 10.0. EPSS: 12.5% chance of exploitation in the next 30 days.

The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access by setting the admin:language cookie to zh-cn.

Affected products

  • Tenda a5s
  • Tenda a5s Firmware: version 3.02.05_cn only

Published 2014-08-22. Last modified 2026-06-17.