First published: Tue Aug 30 2022(Updated: )
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tendacn Ac6 Firmware | <=02.03.01.114 | |
Tendacn Ac6 | =5.0 | |
All of | ||
Tendacn Ac6 Firmware | <=02.03.01.114 | |
Tendacn Ac6 | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36552 is a vulnerability in Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below that allows attackers to steal all data via a crafted GET request.
CVE-2022-36552 has a severity score of 7.5, which is considered high.
An attacker can exploit CVE-2022-36552 by sending a crafted GET request to the /cgi-bin/DownloadFlash component.
Yes, Tenda AC6(AC1200) v5.0 firmware v02.03.01.114 and below is affected by CVE-2022-36552.
To fix CVE-2022-36552, update your Tenda AC6(AC1200) firmware to a version above v02.03.01.114.