CVE-2022-36552: High severity Tendacn Ac6 Firmware vulnerability
Published Aug 30, 2022
·Updated
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which allows attackers to steal all data such as source code and system files via a crafted GET request.
Affected Software
4 affected components
All of the following
Tendacn Ac6 Firmware<=02.03.01.114
Tendacn Ac6=5.0
Tendacn Ac6 Firmware<=02.03.01.114
Tendacn Ac6=5.0
Event History
Aug 30, 2022
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-36552?
CVE-2022-36552 is a vulnerability in Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below that allows attackers to steal all data via a crafted GET request.
2
How severe is CVE-2022-36552?
CVE-2022-36552 has a severity score of 7.5, which is considered high.
3
How can an attacker exploit CVE-2022-36552?
An attacker can exploit CVE-2022-36552 by sending a crafted GET request to the /cgi-bin/DownloadFlash component.
4
Is Tenda AC6(AC1200) v5.0 firmware v02.03.01.114 and below affected by CVE-2022-36552?
Yes, Tenda AC6(AC1200) v5.0 firmware v02.03.01.114 and below is affected by CVE-2022-36552.
5
How do I fix CVE-2022-36552?
To fix CVE-2022-36552, update your Tenda AC6(AC1200) firmware to a version above v02.03.01.114.