First published: Thu Aug 25 2022(Updated: )
Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda Ac1206 Firmware | =15.03.06.23 | |
Tenda AC1206 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37810 is a command injection vulnerability in Tenda AC1206 V15.03.06.23.
CVE-2022-37810 has a severity rating of 9.8 (Critical).
CVE-2022-37810 allows an attacker to execute arbitrary commands via the 'mac' parameter in the 'formWriteFacMac' function.
Yes, Tenda AC1206 V15.03.06.23 is vulnerable to CVE-2022-37810.
To fix CVE-2022-37810, update Tenda AC1206 firmware to a version that is not affected.