CVE-2022-24171: Command Injection
Tenda routers G1 and G3 v15.11.0.17(9502)CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vulnerability allows attackers to execute arbitrary commands via the pppoeServerIP, pppoeServerStartIP, and pppoeServerEndIP parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24171?
CVE-2022-24171 has been classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2022-24171?
To fix CVE-2022-24171, upgrade the Tenda G1 or G3 firmware to the latest version provided by the manufacturer.
What devices are affected by CVE-2022-24171?
CVE-2022-24171 affects Tenda routers G1 and G3 running firmware version 15.11.0.17(9502)_CN.
What type of vulnerability is CVE-2022-24171?
CVE-2022-24171 is a command injection vulnerability, allowing attackers to execute arbitrary commands.
Is CVE-2022-24171 exploitable remotely?
Yes, CVE-2022-24171 is exploitable remotely if the device is accessible over the internet.