An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.
CP3V2.0 - V11.10.00.2311090948
CWE-313: Cleartext Storage in a File or on Disk
Devices affected by this vulnerability can access the passwords of WiFi routers they are connected to through a specific file path. The path in question contains a file where sensitive information, including the WiFi router's password, is stored in plaintext.
The sensitive information can be found at:
/app/userdata/ifcfg.wlan0