CVE-2022-37810: OS Command Injection
Published Aug 25, 2022
·Updated
Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
Affected Software
2 affected components
Tenda Ac1206 Firmware=15.03.06.23
Tenda AC1206
Event History
Aug 25, 2022
CVE Published
via MITRE·02:06 PM
Data Sourced
via MITRE·02:06 PM
Description
Frequently Asked Questions
1
What is CVE-2022-37810?
CVE-2022-37810 is a command injection vulnerability in Tenda AC1206 V15.03.06.23.
2
How severe is CVE-2022-37810?
CVE-2022-37810 has a severity rating of 9.8 (Critical).
3
How does CVE-2022-37810 affect Tenda AC1206 V15.03.06.23?
CVE-2022-37810 allows an attacker to execute arbitrary commands via the 'mac' parameter in the 'formWriteFacMac' function.
4
Is Tenda AC1206 V15.03.06.23 vulnerable to CVE-2022-37810?
Yes, Tenda AC1206 V15.03.06.23 is vulnerable to CVE-2022-37810.
5
How can I fix CVE-2022-37810?
To fix CVE-2022-37810, update Tenda AC1206 firmware to a version that is not affected.