CVE-2019-16213: Tendacn PA6 Firmware

High severity, CVSS 8.8. EPSS: 2.9% chance of exploitation in the next 30 days.

Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted string, an attacker could modify the device name of an attached PLC adapter to inject and execute arbitrary commands on the system with root privileges.

Affected products

  • Tendacn PA6 Firmware: version 1.0.1.21 only

Published 2020-06-25. Last modified 2026-06-17.