CVE-2022-26290: OS Command Injection
Published Mar 23, 2022
·Updated
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/WriteFacMac.
Affected Software
2 affected components
Tenda M3 Firmware=1.0.0.12\(4856\)
Tenda M3
Event History
Mar 23, 2022
CVE Published
via MITRE·11:24 PM
Data Sourced
via MITRE·11:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-26290?
CVE-2022-26290 is classified as a high severity command injection vulnerability.
2
How do I fix CVE-2022-26290?
To fix CVE-2022-26290, you should update the Tenda M3 firmware to the latest version provided by the vendor.
3
What is the impact of CVE-2022-26290?
CVE-2022-26290 can allow an attacker to execute arbitrary commands on the Tenda M3 device remotely.
4
Which devices are affected by CVE-2022-26290?
CVE-2022-26290 affects the Tenda M3 firmware version 1.0.0.12(4856).
5
Is CVE-2022-26290 specific to certain firmware versions?
Yes, CVE-2022-26290 specifically affects Tenda M3 firmware version 1.0.0.12(4856) and earlier versions.