CVE-2022-24170: Command Injection
Published Feb 4, 2022
·Updated
Tenda routers G1 and G3 v15.11.0.17(9502)CN were discovered to contain a command injection vulnerability in the function formSetIpSecTunnel. This vulnerability allows attackers to execute arbitrary commands via the IPsecLocalNet and IPsecRemoteNet parameters.
Affected Software
4 affected components
Tendacn G1 Firmware=15.11.0.17\(9502\)_cn
Tendacn G1
Tendacn G3 Firmware=15.11.0.17\(9502\)_cn
Tendacn G3
Event History
Feb 4, 2022
CVE Published
via MITRE·01:32 AM
Data Sourced
via MITRE·01:32 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Tenda router issue?
The vulnerability ID for this Tenda router issue is CVE-2022-24170.
2
What is the severity level of CVE-2022-24170?
The severity level of CVE-2022-24170 is critical, with a score of 9.8.
3
Which Tenda routers are affected by CVE-2022-24170?
Tenda routers G1 and G3 v15.11.0.17(9502)_CN are affected by CVE-2022-24170.
4
How can attackers exploit CVE-2022-24170?
Attackers can exploit CVE-2022-24170 by executing arbitrary commands via the IPsecLocalNet and IPsecRemoteNet parameters.
5
Is there a fix available for CVE-2022-24170?
At the moment, there is no information available about a fix for CVE-2022-24170. It is recommended to follow vendor advisories for updates and patches.