CVE-2022-31446: OS Command Injection
Published Jun 14, 2022
·Updated
Tenda AC18 router V15.03.05.19 and V15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.
Affected Software
3 affected components
Tendacn Ac18 Firmware=15.03.05.05
Tendacn Ac18 Firmware=15.03.05.19
Tendacn Ac18
Event History
Jun 14, 2022
CVE Published
via MITRE·02:41 AM
Data Sourced
via MITRE·02:41 AM
Description
Frequently Asked Questions
1
What is CVE-2022-31446?
CVE-2022-31446 is a remote code execution (RCE) vulnerability found in Tenda AC18 router V15.03.05.19 and V15.03.05.05.
2
How severe is CVE-2022-31446?
CVE-2022-31446 has a severity rating of 9.8, which is considered critical.
3
How does CVE-2022-31446 exploit work?
CVE-2022-31446 can be exploited through the Mac parameter at ip/goform/WriteFacMac to execute arbitrary code remotely.
4
Which versions of Tenda AC18 router are affected by CVE-2022-31446?
Tenda AC18 router versions V15.03.05.19 and V15.03.05.05 are affected by CVE-2022-31446.
5
Is Tenda AC18 router version V15.03.05.05 vulnerable?
Yes, Tenda AC18 router version V15.03.05.05 is vulnerable to CVE-2022-31446.