First published: Tue Nov 15 2022(Updated: )
In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools. This vulnerability allows attackers to run arbitrary commands on the server via the hostname parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda W15e Firmware | =15.11.0.10\(1576\) | |
Tenda AC1200 V-W15Ev2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40847 is considered a high severity vulnerability due to its ability to allow arbitrary command execution.
To mitigate CVE-2022-40847, update the Tenda AC1200 Router to the latest firmware version that addresses the vulnerability.
CVE-2022-40847 specifically affects the Tenda AC1200 Router model W15Ev2 running firmware version 15.11.0.10(1576).
CVE-2022-40847 can be exploited through command injection via the hostname parameter in the function formSetFixTools.
Attackers exploiting CVE-2022-40847 can execute arbitrary commands on the router, potentially compromising the device and the network it connects to.