A flaw has been found in Tenda CH22 1.0.0.1. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. Executing a manipulation of the argument mac can lead to command injection.
The attack may be launched remotely. The exploit has been published and may be used.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Tenda Ch22_Firmware
cpe:2.3:o:tenda:ch22_firmware:1.0.0.1:*:*:*:*:*:*:*
|
— | — |
|
Tenda Ch22
cpe:2.3:h:tenda:ch22:-:*:*:*:*:*:*:*
|
— | — |