CVE-2022-24168: Command Injection
Tenda routers G1 and G3 v15.11.0.17(9502)CN were discovered to contain a command injection vulnerability in the function formSetIpGroup. This vulnerability allows attackers to execute arbitrary commands via the IPGroupStartIP and IPGroupEndIP parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24168?
CVE-2022-24168 is rated as a high severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2022-24168?
To fix CVE-2022-24168, it is recommended to update the Tenda G1 or G3 firmware to the latest version provided by the manufacturer.
What devices are affected by CVE-2022-24168?
CVE-2022-24168 affects Tenda routers G1 and G3 running firmware version 15.11.0.17(9502)_CN.
What is the nature of the vulnerability in CVE-2022-24168?
CVE-2022-24168 is a command injection vulnerability allowing attackers to execute arbitrary commands via specific input parameters.
Can CVE-2022-24168 be exploited remotely?
Yes, CVE-2022-24168 can be exploited remotely if the affected Tenda devices are accessible over the internet.