CVE-2022-24165: Command Injection
Published Feb 4, 2022
·Updated
Tenda routers G1 and G3 v15.11.0.17(9502)CN were discovered to contain a command injection vulnerability in the function formSetQvlanList. This vulnerability allows attackers to execute arbitrary commands via the qvlanIP parameter.
Affected Software
4 affected components
Tendacn G1 Firmware=15.11.0.17\(9502\)_cn
Tendacn G1
Tendacn G3 Firmware=15.11.0.17\(9502\)_cn
Tendacn G3
Event History
Feb 4, 2022
CVE Published
via MITRE·01:33 AM
Data Sourced
via MITRE·01:33 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-24165?
The severity of CVE-2022-24165 is critical with a score of 9.8.
2
How does CVE-2022-24165 affect Tenda routers G1 and G3?
CVE-2022-24165 affects Tenda routers G1 and G3 by allowing attackers to execute arbitrary commands via the qvlanIP parameter.
3
What is the vulnerability in Tenda routers G1 and G3 related to CVE-2022-24165?
The vulnerability in Tenda routers G1 and G3 related to CVE-2022-24165 is a command injection vulnerability in the function formSetQvlanList.