CVE-2022-41395: OS Command Injection
Published Nov 15, 2022
·Updated
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in the setDMZ function.
Affected Software
4 affected components
Tenda W15e Firmware=15.11.0.10\(1576\)
Tenda W15E=2.0
All of the following
Tenda W15e Firmware=15.11.0.10\(1576\)
Tenda W15E=2.0
Event History
Nov 15, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-41395?
CVE-2022-41395 is considered a high severity vulnerability due to the potential for command injection.
2
How do I fix CVE-2022-41395?
To fix CVE-2022-41395, update the Tenda AC1200 Router to the latest firmware version that addresses this vulnerability.
3
What products are affected by CVE-2022-41395?
CVE-2022-41395 affects Tenda AC1200 Router Model W15Ev2 running version 15.11.0.10(1576).
4
What type of vulnerability is CVE-2022-41395?
CVE-2022-41395 is classified as a command injection vulnerability.
5
Can CVE-2022-41395 be exploited remotely?
Yes, CVE-2022-41395 can be exploited remotely by an attacker who sends a specially crafted request to the vulnerable function.