CVE-2022-24167: Command Injection
Tenda routers G1 and G3 v15.11.0.17(9502)CN were discovered to contain a command injection vulnerability in the function formSetDMZ. This vulnerability allows attackers to execute arbitrary commands via the dmzHost1 parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24167?
CVE-2022-24167 is considered a critical vulnerability due to its potential to allow arbitrary command execution.
How do I fix CVE-2022-24167?
To mitigate CVE-2022-24167, update your Tenda G1 or G3 router firmware to the latest available version.
Which Tenda router models are affected by CVE-2022-24167?
CVE-2022-24167 affects Tenda G1 and G3 routers running firmware version 15.11.0.17(9502)_CN.
What does the CVE-2022-24167 vulnerability exploit?
CVE-2022-24167 exploits a command injection vulnerability in the formSetDMZ function of the affected routers.
Can CVE-2022-24167 be exploited remotely?
Yes, CVE-2022-24167 can be exploited remotely, allowing attackers to execute commands without physical access.