CVE-2022-36273: OS Command Injection
Published Aug 16, 2022
·Updated
Tenda AC9 V15.03.2.21cn is vulnerable to command injection via goform/SetSysTimeCfg.
Affected Software
2 affected components
Tenda Ac9 Firmware=15.03.2.21_cn
Tenda Ac9
Event History
Aug 16, 2022
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36273?
The severity of CVE-2022-36273 is critical with a CVSS score of 9.8.
2
Which Tenda routers are affected by CVE-2022-36273?
Tenda AC9 V15.03.2.21_cn firmware version is affected by CVE-2022-36273.
3
How does CVE-2022-36273 affect Tenda AC9 routers?
CVE-2022-36273 allows attackers to execute arbitrary commands on Tenda AC9 routers via the goform/SetSysTimeCfg function.
4
Is Tenda AC9 firmware version 15.03.2.21_cn vulnerable to CVE-2022-36273?
Yes, Tenda AC9 firmware version 15.03.2.21_cn is vulnerable to CVE-2022-36273.
5
Is there a fix for CVE-2022-36273?
At the moment, there is no official fix available for CVE-2022-36273. It is recommended to update to the latest firmware version once it becomes available.