CVE-2022-27077: Command Injection
Published Mar 23, 2022
·Updated
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinPic.
Affected Software
2 affected components
Tenda M3 Firmware=1.0.0.12\(4856\)
Tenda M3
Event History
Mar 23, 2022
CVE Published
via MITRE·11:25 PM
Data Sourced
via MITRE·11:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-27077?
CVE-2022-27077 is classified as a high severity command injection vulnerability.
2
How do I mitigate CVE-2022-27077?
To mitigate CVE-2022-27077, update the Tenda M3 firmware to the latest version provided by the manufacturer.
3
What are the impacts of CVE-2022-27077?
If exploited, CVE-2022-27077 could allow an attacker to execute arbitrary commands on the vulnerable device.
4
Which firmware versions are affected by CVE-2022-27077?
CVE-2022-27077 specifically affects Tenda M3 firmware version 1.0.0.12(4856).
5
Is there an official fix for CVE-2022-27077?
Yes, the official fix for CVE-2022-27077 is included in the latest firmware release from Tenda.