CVE-2022-32054: OS Command Injection
Published Jul 7, 2022
·Updated
Tenda AC10 USAC10V1.0RTLV15.03.06.26multiTD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter.
Affected Software
2 affected components
Tenda Ac10 Firmware=15.03.06.26
Tenda AC10=1.0
Remediation
Event History
Jul 7, 2022
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
Description
Frequently Asked Questions
1
What is CVE-2022-32054?
CVE-2022-32054 is a remote code execution (RCE) vulnerability found in Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 firmware.
2
How severe is CVE-2022-32054?
CVE-2022-32054 has a severity rating of 9.8, which is classified as critical.
3
How does CVE-2022-32054 work?
CVE-2022-32054 allows attackers to execute remote code by exploiting the 'lanIp' parameter in Tenda AC10 firmware.
4
Is Tenda AC10 firmware version 15.03.06.26 vulnerable?
Yes, Tenda AC10 firmware version 15.03.06.26 is vulnerable to CVE-2022-32054.
5
How can I fix CVE-2022-32054?
To fix CVE-2022-32054, update Tenda AC10 firmware to a version that is not affected.